Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited Months Before Disclosure

2026-06-25T14:51:44Z957728ff8a22143dd5860ed57d2a8d3b636a5b9c5267d690575bb7678b905047
AI securityAmadeyCISACVECiscoCisco Catalyst SD-WANCisco Unified CMDifyDifyTapDraftKingsEuropolFortiBleedFortinetGSM-R outageKNOXKnown Exploited VulnerabilitiesLantronix EDS5000Operation EndgameSamsungStealCUbiquiti UniFiactively-exploitedcredential stuffingvulnerabilityzero-day

What happened

Recent security reporting highlights multiple high-impact incidents and active exploitations: Mandiant observed an unknown actor exploiting Cisco Catalyst SD‑WAN zero-day CVE-2026-20245 months before disclosure, enabling privileged command execution. Cisco Unified Communications Manager has an actively exploited flaw CVE-2026-20230 (SSRF → file write → root, CVSS 8.6). Samsung KNOX suffers a kernel use-after-free (CVE-2026-20971) affecting millions of Galaxy devices (patched). Dify (open-source AI platform) has four vulnerabilities (two critical) that exposed cross-tenant data and allowed una‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
957728ff8a22143dd5860ed57d2a8d3b636a5b9c5267d690575bb7678b905047
Enrichment time
2026-06-25T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.