Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026
2026-06-05T07:24:08Z•bef27361f39ffc349602ecc4d2d0f9364f937ef5591983b38b747864857edba1
CVE-2026-20245CiscoGeminiMagentoMirasvitRCESD-WANSSRFTA4922Unified CMVS Codearbitrary-code-executioncybercrimelaw-enforcementproof-of-conceptsecuritynewsthreat-actorstoken-theftvoice-assistantvulnerabilityzero-day
What happened
Feed highlights multiple high-impact security stories. Principal item: Cisco warns of a 7th SD‑WAN zero‑day (CVE-2026-20245) that enables arbitrary command execution as root with no patch available. Other notable items: Cisco reports an available PoC for a critical Unified CM SSRF issue; a VS Code flaw with public PoC can steal GitHub tokens; a Mirasvit Magento extension is being exploited for unauthenticated RCE via serialized PHP objects; and a Gemini voice assistant messaging-notification flaw can hijack actions (smart home control, starting Zoom). Also included: threat actor activity (TA/9
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- bef27361f39ffc349602ecc4d2d0f9364f937ef5591983b38b747864857edba1
- Enrichment time
- 2026-06-05T07:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.