Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 exploited for root two months before disclosure
Anyone running Cisco $CSCO Catalyst SD-WAN Manager should check their logs now. Mandiant says an attacker exploited CVE-2026-20245, a command-injection flaw in vManage, as a zero-day for about two months before disclosure, uploading a malicious CSV to run commands as root. Fixed
Anyone running Cisco $CSCO Catalyst SD-WAN Manager has reason to review their systems this week. Google-owned Mandiant reports that an unknown threat actor exploited CVE-2026-20245, a command-injection flaw in the vManage command-line interface, as a zero-day for roughly two months before it was publicly disclosed. In the observed intrusion the attacker first changed default admin credentials, then uploaded a malicious CSV file to execute commands as root, giving control over the entire SD-WAN management plane. The flaw carries a CVSS score of 7.8 and requires netadmin privileges, which attackers can obtain through stolen credentials or by chaining older Cisco vulnerabilities. Because SD-WAN managers sit at the center of a network, a compromise here is not one device but the connective tissue linking every branch and data centre. The two-month gap between first exploitation and disclosure meant defenders were blind to it throughout that window. Cisco has released fixed software; the exposure lasts as long as unpatched controllers stay online. Source: The Hacker News.