CVE Tools

Cisco SD-WAN Zero-Day Exploited in Attacks

Daily CyberSecurity (securityonline.info)

Reported exploitedCisco Catalyst SD-WAN Manager

Our summary

An unnamed threat actor exploited a Cisco SD-WAN zero-day against service provider infrastructure, with Mandiant reporting evidence of compromise. The attackers targeted Cisco Catalyst SD-WAN Manager and used a malicious CSV upload path to trigger CVE-2026-20245, ultimately escalating to root-level control and conducting anti-forensic actions. Organizations running affected Cisco SD-WAN components should upgrade to the fixed releases listed by the vendor to eliminate CVE-2026-20245 risk and reduce further intrusion likelihood.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store