• News/
  • bleepingcomputer-20260624212910

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

BleepingComputer
·
Lawrence Abrams
·
Published Jun 24, 2026
·
Updated

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. The CVE-2026-20245 vulnerability is a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond) that allows authenticated attackers to execute arbitrary commands as root by uploading a crafted file. Cisco said the vulnerability stemmed from insufficient validation of user-supplied input and could be exploited by authenticated attackers with local access to affected devices. When Cisco disclosed the flaw earlier this month, the company warned that it had been exploited in a limited number of attacks but did not provide any details. Cisco only stated that successful exploitation allowed attackers to gain root privileges and that some incidents involved unauthorized configuration changes being pushed to edge devices. The company released security updates and urged customers to upgrade to fixed software versions, stating that no workarounds were available. In a report published today, Mandiant revealed that CVE-2026-20245 was exploited as a privilege-escalation vulnerability after attackers had already gained access to targeted SD-WAN devices. According to the researchers, the intrusion began with unauthorized SD-WAN peering connections observed on a service provider's infrastructure. Beginning in March 2026, the threat actor ...

Read full article

Affected Software

3 affected components
Cisco Catalyst SD-WAN Manager (vManage)
Cisco Catalyst SD-WAN Controller (vSmart)
Cisco Catalyst SD-WAN Validator (vBond)

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how hackers exploited a Cisco SD-WAN zero-day vulnerability to gain root access on devices.

2

What specific vulnerability is highlighted in the article?

The highlighted vulnerability is CVE-2026-20245, which is a high-severity command injection flaw in Cisco's SD-WAN Manager.

3

What types of Cisco products are affected by this vulnerability?

The affected products include Cisco Catalyst SD-WAN Manager (vManage), SD-WAN Controller (vSmart), and SD-WAN Validator (vBond).

4

What attack method did the hackers use to exploit the vulnerability?

The hackers used a command injection technique to create rogue root accounts on the targeted devices.

5

How critical is the CVE-2026-20245 vulnerability?

CVE-2026-20245 is classified as a high-severity vulnerability, indicating significant risk to the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203