Return to Threats

Cisco SD-WAN Zero-Day Exploited Months Before Patching

securityweek.com 2026-06-25 AI supply chain Critical

What Happened

CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek .

Why It Matters

The article reports that CVE-2026-20245, a zero-day in the CLI of Cisco Catalyst SD-WAN Manager and related components, was exploited for months before public disclosure and patch availability, making it the seventh SD-WAN zero-day exploited in 2026.[1][4][6] The flaw allows an authenticated attacker with netadmin-level access to execute arbitrary commands as root via a crafted file, giving full control over the SD-WAN management plane.[1][2][6] From a CyberSE.AI perspective, this illustrates a critical third-party infrastructure risk for any AI workloads, agents, or data flows that traverse or depend on SD-WAN fabric, and highlights the need to treat network controllers as key elements in the AI supply chain. Organizations should maintain SBOM-level visibility into SD-WAN and other control-plane components, integrate vendor zero-day monitoring into AI risk management, and include SD-WAN compromise scenarios in continuous AI red teaming to understand potential lateral movement paths into AI agents, models, and training data environments.

Healthcare Fintech SaaS SMB AI startups

CyberSE Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://www.securityweek.com/cisco-sd-wan-zero-day-exploited-months-before-patching/

Talk to AI CISO