Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited Months Before Disclosure
2026-06-25T14:51:44Z•957728ff8a22143dd5860ed57d2a8d3b636a5b9c5267d690575bb7678b905047
AI securityAmadeyCISACVECiscoCisco Catalyst SD-WANCisco Unified CMDifyDifyTapDraftKingsEuropolFortiBleedFortinetGSM-R outageKNOXKnown Exploited VulnerabilitiesLantronix EDS5000Operation EndgameSamsungStealCUbiquiti UniFiactively-exploitedcredential stuffingvulnerabilityzero-day
What happened
Recent security reporting highlights multiple high-impact incidents and active exploitations: Mandiant observed an unknown actor exploiting Cisco Catalyst SD‑WAN zero-day CVE-2026-20245 months before disclosure, enabling privileged command execution. Cisco Unified Communications Manager has an actively exploited flaw CVE-2026-20230 (SSRF → file write → root, CVSS 8.6). Samsung KNOX suffers a kernel use-after-free (CVE-2026-20971) affecting millions of Galaxy devices (patched). Dify (open-source AI platform) has four vulnerabilities (two critical) that exposed cross-tenant data and allowed una‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 957728ff8a22143dd5860ed57d2a8d3b636a5b9c5267d690575bb7678b905047
- Enrichment time
- 2026-06-25T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.