logo

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

ID: 84390c32-8faa-5e05-a51d-5d569613fc19

STIX ID: report--84390c32-8faa-5e05-a51d-5d569613fc19

Feed Name: Google Cloud Threat Intelligence

Threat Score
88/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Mandiant

...
...

Mandiant observed a threat actor targeting Cisco Catalyst SD-WAN at a service provider in early 2026: the attacker established rogue peering and SSH access, manipulated admin credentials to access the management interface, exploited a zero-day (CVE-2026-20245) via malicious CSV upload to escalate to root, exfiltrated SD-WAN configurations, and performed anti-forensic cleanup to remove traces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.