← Back to Feed
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
CVE-2026-20245
June 24, 2026 · Google Cloud Security · Severity: CRITICAL
This article details a threat actor's exploitation of CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, escalating from a compromised admin account to root via a malicious CSV upload. The attacker maintained operational security through anti-forensic techniques and the article also explains the basics of SD-WAN technology.
Key Takeaways
- Zero-day CVE-2026-20245 exploited in Cisco Catalyst SD-WAN Manager for privilege escalation to root.
- Attacker used rogue peering and credential manipulation to gain initial access and evade detection.
- Anti-forensic measures included deleting files, reverting configs, and running validation scripts to purge evidence.