Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
2026-06-06T07:24:08Z•b6fe7671a402b57580ed395e9d2835bc21dc9a11f2ded257e2729cdcca1ddbc8
active-exploitationandroid-spywarecisa-kevcloud-compromiseexploit-code-publicmagentomalvertisingmalwareno-patchnpmoauth-token-theftphishingremote-code-executionsmtp-relay-abusespywaresupply-chainthreat-actorvulnerabilityweb-shellwordPressworm
What happened
A broad set of active, high-impact threats and vulnerabilities were reported across enterprise and open-source ecosystems. Key highlights: Cisco Catalyst SD‑WAN Manager (CVE-2026-20245) is under active exploitation with no patch available; multiple high-severity RCEs are being exploited or tracked (Everest Forms Pro CVE-2026-3300, Mirasvit/Magento CVE-2026-45247 added to CISA KEV), and proof‑of‑concept exploit code for Cisco Unified CM (CVE-2026-20230) is public. Supply‑chain attacks hit npm (IronWorm and a Miasma worm variant) and malicious/poisoned packages are distributing stealers and self
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b6fe7671a402b57580ed395e9d2835bc21dc9a11f2ded257e2729cdcca1ddbc8
- Enrichment time
- 2026-06-06T07:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.