← Back to Feed

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

CVE-2026-20245

June 24, 2026 · Google Cloud Security · Severity: CRITICAL

Mandiant identified a threat actor targeting SD-WAN infrastructure who exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to escalate privileges to root. The attacker used rogue peering for initial access and employed extensive anti-forensic cleanup to avoid detection.

Key Takeaways

  • Threat actor exploited CVE-2026-20245 zero-day in Cisco Catalyst SD-WAN Manager for privilege escalation.
  • Initial access gained via rogue peering connections and credential manipulation to evade detection.
  • Anti-forensic techniques included deleting files, reverting changes, and running validation scripts to purge indicators.
☕ Buy a Coffee