New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. The CVE-2026-20245 vulnerability is a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond) that allows authenticated attackers to execute arbitrary commands as root by uploading a crafted file. Cisco said the vulnerability stemmed from insufficient validation of user-supplied input and could be exploited by authenticated attackers with local access to affected devices. When Cisco disclosed the flaw earlier this month, the company warned that it had been exploited in a limited number of attacks but did not provide any details. Cisco only stated that successful exploitation allowed attackers to gain root privileges and that some incidents involved unauthorized configuration changes being pushed to edge devices. The company released security updates and urged customers to upgrade to fixed software versions, stating that no workarounds were available. In a report published today, Mandiant revealed that CVE-2026-20245 was exploited as a privilege-escalation vulnerability after attackers had already gained access to targeted SD-WAN devices. According to the researchers, the intrusion began with unauthorized SD-WAN peering connections observed on a service provider's infrastructure. Beginning in March 2026, the threat actor ...
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
BleepingComputer
·Lawrence Abrams
·Published Jun 24, 2026
·Updated
Affected Software
3 affected components
Cisco Catalyst SD-WAN Manager (vManage)
Cisco Catalyst SD-WAN Controller (vSmart)
Cisco Catalyst SD-WAN Validator (vBond)
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how hackers exploited a Cisco SD-WAN zero-day vulnerability to gain root access on devices.
2
What specific vulnerability is highlighted in the article?
The highlighted vulnerability is CVE-2026-20245, which is a high-severity command injection flaw in Cisco's SD-WAN Manager.
3
What types of Cisco products are affected by this vulnerability?
The affected products include Cisco Catalyst SD-WAN Manager (vManage), SD-WAN Controller (vSmart), and SD-WAN Validator (vBond).
4
What attack method did the hackers use to exploit the vulnerability?
The hackers used a command injection technique to create rogue root accounts on the targeted devices.
5
How critical is the CVE-2026-20245 vulnerability?
CVE-2026-20245 is classified as a high-severity vulnerability, indicating significant risk to the affected systems.