Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
ID: 6523710e-50f4-5e7f-9462-4fe37831cd90
STIX ID: report--6523710e-50f4-5e7f-9462-4fe37831cd90
Feed Name: The Hacker News
Mandiant (Google) disclosed that an unknown actor exploited a high-severity zero-day (CVE-2026-20245, CVSS 7.8) in Cisco Catalyst SD-WAN to escalate a netadmin account to root via a malicious CSV upload (evil_tenant.csv), create a hidden 'troot' account, exfiltrate SD-WAN fabric configuration, and employ anti-forensic techniques; earlier and separate waves likely exploited other undisclosed authentication bypass zero-days (CVE-2026-20127 / CVE-2026-20182) to establish rogue peering on a communications service provider between late 2025 and March 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
