CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 306

As cited

Copy frozen at (site build).

vulnerabilities

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Mandiant identified threat actors exploiting a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to escalate from compromised administrative accounts to root-level access via malicious file uploads. The attackers established initial access through unauthorized peering connections, manipulated credentials, and employed extensive anti-forensic techniques to cover their tracks. The vulnerability stems from inadequate filtering in the device's file upload feature, affecting SD-WAN infrastructure used by distributed organizations like banks, retail, and healthcare providers.

Why it matters: SD-WAN administrators should immediately verify their Cisco Catalyst SD-WAN Manager versions against CVE-2026-20245 patches and review peering connections and file upload activities for signs of compromise, as root-level access enables complete infrastructure control.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Mandiant identified a threat actor exploiting CVE-2026-20245, a zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows privilege escalation from administrative to root access via malicious CSV file uploads. The attacker gained initial access through unauthorized peering connections starting in late 2025, manipulated credentials, and conducted extensive anti-forensic cleanup to avoid detection. The vulnerability affects SD-WAN infrastructure used by distributed organizations including banks, retailers, and healthcare providers to centrally manage multi-location networks.

Why it matters: Organizations running Cisco Catalyst SD-WAN Manager are immediately exposed to root-level compromise if they have not patched CVE-2026-20245; practitioners should verify their device versions, audit peering connections for unauthorized entries, and review logs for evidence of malicious CSV uploads or configuration changes from March 2026 onward.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Mandiant identified a threat actor exploiting CVE-2026-20245, a zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows privilege escalation from administrative to root access via malicious CSV file uploads. The attacker gained initial access through unauthorized peering connections starting in late 2025, manipulated credentials, and conducted extensive anti-forensic cleanup to avoid detection. The vulnerability affects SD-WAN infrastructure used by distributed organizations including banks, retailers, and healthcare providers to centrally manage multi-location networks.

Why it matters: Organizations running Cisco Catalyst SD-WAN Manager are immediately exposed to root-level compromise if they have not patched CVE-2026-20245; practitioners should verify their device versions, audit peering connections for unauthorized entries, and review logs for evidence of malicious CSV uploads or configuration changes from March 2026 onward.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary