As cited
Copy frozen at (site build).
vulnerabilities
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
Mandiant identified threat actors exploiting a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to escalate from compromised administrative accounts to root-level access via malicious file uploads. The attackers established initial access through unauthorized peering connections, manipulated credentials, and employed extensive anti-forensic techniques to cover their tracks. The vulnerability stems from inadequate filtering in the device's file upload feature, affecting SD-WAN infrastructure used by distributed organizations like banks, retail, and healthcare providers.
Why it matters: SD-WAN administrators should immediately verify their Cisco Catalyst SD-WAN Manager versions against CVE-2026-20245 patches and review peering connections and file upload activities for signs of compromise, as root-level access enables complete infrastructure control.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
Mandiant identified a threat actor exploiting CVE-2026-20245, a zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows privilege escalation from administrative to root access via malicious CSV file uploads. The attacker gained initial access through unauthorized peering connections starting in late 2025, manipulated credentials, and conducted extensive anti-forensic cleanup to avoid detection. The vulnerability affects SD-WAN infrastructure used by distributed organizations including banks, retailers, and healthcare providers to centrally manage multi-location networks.
Why it matters: Organizations running Cisco Catalyst SD-WAN Manager are immediately exposed to root-level compromise if they have not patched CVE-2026-20245; practitioners should verify their device versions, audit peering connections for unauthorized entries, and review logs for evidence of malicious CSV uploads or configuration changes from March 2026 onward.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
Mandiant identified a threat actor exploiting CVE-2026-20245, a zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows privilege escalation from administrative to root access via malicious CSV file uploads. The attacker gained initial access through unauthorized peering connections starting in late 2025, manipulated credentials, and conducted extensive anti-forensic cleanup to avoid detection. The vulnerability affects SD-WAN infrastructure used by distributed organizations including banks, retailers, and healthcare providers to centrally manage multi-location networks.
Why it matters: Organizations running Cisco Catalyst SD-WAN Manager are immediately exposed to root-level compromise if they have not patched CVE-2026-20245; practitioners should verify their device versions, audit peering connections for unauthorized entries, and review logs for evidence of malicious CSV uploads or configuration changes from March 2026 onward.
- Source published
- First seen by Cybersecurity Tracker