Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level Access
ID: f9cd9b60-1a4f-5ad9-b70f-6a9c92be24e2
STIX ID: report--f9cd9b60-1a4f-5ad9-b70f-6a9c92be24e2
Feed Name: cybersecurityNews.com
## Executive summary A sophisticated, likely state-sponsored threat actor conducted an active campaign against Cisco Catalyst SD-WAN Manager, leveraging multiple flaws including an authenticated zero-day (CVE-2026-20245) in the CLI file-upload path to inject a UID 0 'troot' account via a crafted CSV, escalate to root, exfiltrate management-plane device configurations, and then clean up forensic artifacts; the report includes IoCs (several IPs), affected releases, and urgent mitigation steps (specific fixed versions, log collection, IOC sweeps, and contacting Cisco TAC).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
