Cisco Catalyst SD-WAN Manager zero-day (CVE-2026-20245) exploited for root access
A command injection zero-day in Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20245, let authenticated attackers upload a crafted file and run commands as root. Mandiant found it was exploited quietly for at least two months, with intruders planting a hidden admin account an
Cisco has confirmed active exploitation of CVE-2026-20245, a command injection flaw in Cisco Catalyst SD-WAN Manager, Controller and Validator that lets an authenticated attacker upload a crafted file and execute commands as root. Security firm Mandiant, part of Google Cloud, traced two waves of intrusion abusing a tenant-upload feature with a malicious file disguised as a spreadsheet. Attackers changed default admin credentials, escalated to root, created a rogue account named troot, then deleted files and reversed configuration changes to erase evidence. The flaw ran as a zero-day for at least two months before disclosure. Cisco urges upgrading to fixed releases (20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2 or later) and auditing for unrecognized accounts. Sources: The Hacker News, Google Cloud/Mandiant, BleepingComputer, Cybersecurity Dive, SecurityWeek.