cloud.google.com 6/24/2026, 2:42:01 PM · external

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
Developing story vulnerability 13 articles tracked
Zero‑day exploitation of Cisco Catalyst SD‑WAN Manager flaw (CVE-2026-20245)
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

IN June 2026, Mandiant reported on a threat actor exploiting a zero-day vulnerability (CVE-2026-20245) in the Cisco Catalyst SD-WAN Manager. This vulnerability allowed the attacker to escalate privileges from a compromised admin account to root access by uploading a malicious CSV file. The actor maintained low visibility by employing anti-forensic techniques, such as altering and restoring system files.

Key observations included unauthorized peering for initial access, manipulation of administrative credentials, and extensive cleanup efforts to erase traces of their activities. The findings highlight vulnerabilities in SD-WAN infrastructure, emphasizing the need for immediate patching and hardening of security protocols to prevent similar intrusions in the future.

View Primary Source Via cloud.google.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline