Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet

2026-06-05T14:51:45Z40bc3f4e07529f39202c10cfd3772d050eff3e4ddb0916eeae996fb88e567cda
cisa-kevciscocisco-sd-wancisco-unified-cmcloud-abusecve-2026-20230cve-2026-20245cve-2026-45247disclosure-politicsemail-relayespionagefake-context-alignmentgamaredongoogle-geminilaw-enforcementmirasvitoperation-kratosoutlook-compromisepcpjackprompt-injectionsmart-homevs-code-zero-daywinrar

What happened

Multiple high-impact security developments: Cisco disclosed a privilege-escalation/file-upload command-injection in Catalyst SD‑WAN Manager (CVE-2026-20245) allowing authenticated attackers root access with no patch/workaround yet; Cisco also patched a high-severity SSRF in Unified CM with public PoC published (CVE-2026-20230). CISA added a critical Mirasvit Full Page Cache Warmer flaw (CVE-2026-45247, CVSS 9.3) to its KEV catalog. Researchers exposed a 230-node cloud email-relay network used by actor PCPJack, and Gamaredon leveraged a WinRAR flaw to deploy modular, near-fileless spyware in a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
40bc3f4e07529f39202c10cfd3772d050eff3e4ddb0916eeae996fb88e567cda
Enrichment time
2026-06-05T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet · Baitaphish