VulnerabilityBleeping Computer
10.0 — CRITICAL
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A zero-day vulnerability in Cisco Catalyst SD-WAN (CVE-2026-20245) was exploited by attackers to gain root access, allowing them to execute arbitrary commands and modify configuration files. The attack involved establishing unauthorized peering connections, authenticating with the vmanage-admin account, and uploading a malicious CSV file.
⚙️Technical Details
CVEs
CVE-2026-20245CVE-2026-20127CVE-2026-20182Affected Systems: Cisco Catalyst SD-WAN Manager, Controller, and ValidatorAttack Vectors: NETWORK
Affected Systems
Cisco Catalyst SD-WAN Manager, Controller, and Validator
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Collect diagnostic data from SD-WAN devices and check for signs of unauthorized peering connections.
2Upgrade to the latest software releases if they have not already done so.
3Monitor for suspicious activity and implement additional security controls as needed.
📦Affected Products
Cisco Catalyst Sd-Wan ManagerCisco Sd-Wan Vbond OrchestratorCisco Sd-Wan Vsmart ControllerCisco Catalyst SD-WAN Manager, Controller, and Validator
🔐NVD Verified DataVERIFIED
CVE-2026-20127 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-287
Affected Products (CPE)
Cisco Catalyst Sd-Wan ManagerCisco Sd-Wan Vbond OrchestratorCisco Sd-Wan Vsmart Controller
CVE-2026-20182 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-287
Affected Products (CPE)
Cisco Catalyst Sd-Wan ManagerCisco Sd-Wan Vbond OrchestratorCisco Sd-Wan Vsmart Controller
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
