← Back to Feed

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

CVE-2026-20245

June 24, 2026 · Google Cloud Security · Severity: CRITICAL

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction  In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.

Key Takeaways

  • Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026.
  • Extensive Anti-Forensic Cleanup: The threat actor deleted malicious files, reverted configuration changes, and.
☕ Buy a Coffee