Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
Summary
Cisco Catalyst SD-WAN faced a zero-day exploit that let an authenticated local attacker gain elevated privileges and root access. Mandiant says the attacker used a malicious CSV upload, created a hidden admin account, and repeatedly deleted traces to stay hidden. The incident hit an unspecified communications service provider and involved multiple unauthorized access waves across late 2025, January 2026, and March 2026. The case highlights how edge devices like SD-WAN systems remain attractive targets because they often lack deep forensic telemetry and EDR coverage.
Classifications
industries
No industries detected
applications
Business Intelligence
AskAI Classifications
Labels
SaaS
Enterprise Software
Collaboration Software
Linked Companies
Cisco
$1B+