logo

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

ID: 575ff6af-ec23-5fa7-b26b-84fca9346fab

STIX ID: report--575ff6af-ec23-5fa7-b26b-84fca9346fab

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Lawrence Abrams

...
...

New details reveal that CVE-2026-20245, a high-severity command-injection flaw in Cisco Catalyst SD-WAN Manager/Controller/Validator, was exploited in the wild to create a rogue root account by uploading a malicious CSV. Mandiant's report shows attackers first established unauthorized SD-WAN peering, likely leveraging earlier authentication bypasses, escalated privileges by exploiting the CSV upload vector, exfiltrated configuration data, and used anti-forensic techniques to hide their activity; IoCs and remediation guidance have been published and Cisco released security updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.