← Back to Feed
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
CVE-2026-20245
June 24, 2026 · Google Cloud Security · Severity: CRITICAL
Mandiant identified a threat actor targeting SD-WAN infrastructure who exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to escalate privileges to root. The attacker used rogue peering for initial access and employed extensive anti-forensic cleanup to avoid detection.
Key Takeaways
- Threat actor exploited CVE-2026-20245 zero-day in Cisco Catalyst SD-WAN Manager for privilege escalation.
- Initial access gained via rogue peering connections and credential manipulation to evade detection.
- Anti-forensic techniques included deleting files, reverting changes, and running validation scripts to purge indicators.