Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

General News

Summary

Cisco Catalyst SD-WAN faced a zero-day exploit that let an authenticated local attacker gain elevated privileges and root access. Mandiant says the attacker used a malicious CSV upload, created a hidden admin account, and repeatedly deleted traces to stay hidden. The incident hit an unspecified communications service provider and involved multiple unauthorized access waves across late 2025, January 2026, and March 2026. The case highlights how edge devices like SD-WAN systems remain attractive targets because they often lack deep forensic telemetry and EDR coverage.

Classifications

industries
No industries detected
applications
Business Intelligence

AskAI Classifications

Labels
SaaS Enterprise Software Collaboration Software

Linked Companies

Cisco
$1B+