logo

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

ID: 6523710e-50f4-5e7f-9462-4fe37831cd90

STIX ID: report--6523710e-50f4-5e7f-9462-4fe37831cd90

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: [email protected] (The Hacker News)

...
...

Mandiant (Google) disclosed that an unknown actor exploited a high-severity zero-day (CVE-2026-20245, CVSS 7.8) in Cisco Catalyst SD-WAN to escalate a netadmin account to root via a malicious CSV upload (evil_tenant.csv), create a hidden 'troot' account, exfiltrate SD-WAN fabric configuration, and employ anti-forensic techniques; earlier and separate waves likely exploited other undisclosed authentication bypass zero-days (CVE-2026-20127 / CVE-2026-20182) to establish rogue peering on a communications service provider between late 2025 and March 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.