Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
ID: 575ff6af-ec23-5fa7-b26b-84fca9346fab
STIX ID: report--575ff6af-ec23-5fa7-b26b-84fca9346fab
Feed Name: Bleeping Computer
New details reveal that CVE-2026-20245, a high-severity command-injection flaw in Cisco Catalyst SD-WAN Manager/Controller/Validator, was exploited in the wild to create a rogue root account by uploading a malicious CSV. Mandiant's report shows attackers first established unauthorized SD-WAN peering, likely leveraging earlier authentication bypasses, escalated privileges by exploiting the CSV upload vector, exfiltrated configuration data, and used anti-forensic techniques to hide their activity; IoCs and remediation guidance have been published and Cisco released security updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
