Cisco SD‑WAN Manager and Linux Kernel Flaws Enable Active Root Exploits
Cisco has disclosed an actively exploited, high‑severity vulnerability (CVE‑2026‑20245) in its Catalyst SD‑WAN Manager. The flaw allows a locally authenticated attacker to upload a crafted file that triggers command‑injection and gains root privileges. No dedicated patch exists; Cisco advises upgrading to fixes released on 14 May 2026. The CVSS score is 7.8, and exploitation requires prior net‑admin credentials.
Separately, researchers have identified a kernel‑level vulnerability dubbed CIFSwitch that affects the Linux CIFS subsystem and cifs‑utils (kernel 6.14+). The defect lets unprivileged users manipulate the authentication workflow to trigger a privileged helper program, ultimately loading malicious code with root rights. The issue, present since 2007, impacts major distributions such as Linux Mint, CentOS Stream, Rocky Linux, AlmaLinux and Kali Linux.
Both flaws illustrate how weaknesses in management interfaces and kernel modules can be chained to achieve full system compromise, prompting urgent remediation across enterprise and open‑source environments.