VMTech
Discuss a project

CVE-2026-20245: zero-day in Cisco Catalyst SD‑WAN led to root

CVE-2026-20245: zero-day in Cisco Catalyst SD‑WAN led to root

Colleagues: Mandiant reports exploitation of CVE-2026-20245 in Cisco Catalyst SD‑WAN, resulting in root access.

Key facts:
— Required netadmin privileges; attacker uploaded crafted CSV (evil_tenant.csv) to escalate.
— Hidden account 'troot' created; configuration exfiltrated; anti‑forensic actions (file deletion, password rollback) observed.
— Activity in two waves (late 2025–Jan 2026 and March 2026); stolen certificates and other unknown bugs possible.

Why it matters: network device flaws enable persistent access and complicate forensics.

How will you validate your SD‑WAN and improve defenses?

#cybersecurity #SDWAN #Cisco #infosec

Open analytics
On the site 0 views
min read 1 28.06.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

CVE-2026-20245: zero-day in Cisco Catalyst SD‑WAN led to root

Open the post on Instagram ↗