Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
ID: 84390c32-8faa-5e05-a51d-5d569613fc19
STIX ID: report--84390c32-8faa-5e05-a51d-5d569613fc19
Feed Name: Google Cloud Threat Intelligence
Threat Score
Mandiant observed a threat actor targeting Cisco Catalyst SD-WAN at a service provider in early 2026: the attacker established rogue peering and SSH access, manipulated admin credentials to access the management interface, exploited a zero-day (CVE-2026-20245) via malicious CSV upload to escalate to root, exfiltrated SD-WAN configurations, and performed anti-forensic cleanup to remove traces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
