CVE Tools

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

BleepingComputerBy Lawrence Abrams

Reported exploitedCisco Catalyst SD-WAN

Our summary

Mandiant has detailed how attackers exploited Cisco Catalyst SD-WAN command injection vulnerability CVE-2026-20245 to escalate privileges to root during zero-day attacks. The issue affects Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond), enabling authenticated attackers to execute arbitrary commands as root by uploading a crafted file—leading to actions such as creating a rogue root account, altering credentials, and exfiltrating configuration data. This matters because it demonstrates a reliable path from initial access to full device control, with anti-forensic steps that can make detection and incident response harder.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store