Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026

2026-06-05T07:24:08Zbef27361f39ffc349602ecc4d2d0f9364f937ef5591983b38b747864857edba1
CVE-2026-20245CiscoGeminiMagentoMirasvitRCESD-WANSSRFTA4922Unified CMVS Codearbitrary-code-executioncybercrimelaw-enforcementproof-of-conceptsecuritynewsthreat-actorstoken-theftvoice-assistantvulnerabilityzero-day

What happened

Feed highlights multiple high-impact security stories. Principal item: Cisco warns of a 7th SD‑WAN zero‑day (CVE-2026-20245) that enables arbitrary command execution as root with no patch available. Other notable items: Cisco reports an available PoC for a critical Unified CM SSRF issue; a VS Code flaw with public PoC can steal GitHub tokens; a Mirasvit Magento extension is being exploited for unauthenticated RCE via serialized PHP objects; and a Gemini voice assistant messaging-notification flaw can hijack actions (smart home control, starting Zoom). Also included: threat actor activity (TA/9

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
bef27361f39ffc349602ecc4d2d0f9364f937ef5591983b38b747864857edba1
Enrichment time
2026-06-05T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.