CVE-2026-20245: zero-day in Cisco Catalyst SD‑WAN led to root

Colleagues: Mandiant reports exploitation of CVE-2026-20245 in Cisco Catalyst SD‑WAN, resulting in root access.
Key facts:
— Required netadmin privileges; attacker uploaded crafted CSV (evil_tenant.csv) to escalate.
— Hidden account 'troot' created; configuration exfiltrated; anti‑forensic actions (file deletion, password rollback) observed.
— Activity in two waves (late 2025–Jan 2026 and March 2026); stolen certificates and other unknown bugs possible.
Why it matters: network device flaws enable persistent access and complicate forensics.
How will you validate your SD‑WAN and improve defenses?
#cybersecurity #SDWAN #Cisco #infosec

