www.securityweek.com 6/25/2026, 6:30:51 AM · external

Cisco SDWAN flaw lets attackers run root commands, Mandiant warns

Cisco SDWAN flaw lets attackers run root commands, Mandiant warns
Developing story vulnerability 16 articles tracked
Zero‑day exploit of Cisco Catalyst SD‑WAN Manager (CVE-2026-20245) grants root access
CyberSIXT Evidence Panel
Primary Source cloud.google.com
CISA KEV Listed in KEV
Patch Patch Available

GOOGLE'S Mandiant team has disclosed the exploitation of a Cisco Catalyst SD-WAN vulnerability, CVE-2026-20245, which allowed local authenticated attackers to execute arbitrary commands with root privileges. This flaw, the seventh SD-WAN product flaw identified in 2026, was exploited months before it was publicly reported. The attacker gained initial access via SSH in March 2026 and used this access to escalate privileges by manipulating the system's settings.

To avoid detection, the attacker deleted files and restored system configurations post-exploitation. Mandiant highlighted the trend of targeting network appliances as part of a strategy to bypass traditional security measures.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline