Zero day at Cisco SD WAN exposes privilege escalation and the hidden troot account threatening the supply chain

Author: Published 4 min de lectura 163 reading

The images in this article were generated with artificial intelligence. How we publish

A recent report by Mandiant, the Google-owned response and intelligence unit, reveals that an unknown actor exploded as zero-day a high severity failure in Cisco Catalyst SD-WAN at least two months before its public disclosure. Vulnerability, recorded as CVE-2026-20245(CVSS 7.8), allows an authenticated local attacker to run commands with high privileges by loading a specially designed file that takes advantage of insufficient user input validation.

The findings describe a campaign directed against a communications service provider in which two separate waves of unauthorized activity were detected: one between the end of 2025 and January 2026, and one in March 2026. During the first stage the attackers probably abused authentication vulnerabilities not yet disclosed (CVE-2026-20127 or CVE-2026-20182) to create rogue peering connections; in the second stage, after updating the software of a device, they did not use those same faults but could resort to stolen certificates and the exploitation of CVE-2026-20245 by raising a malicious CSV (evil _ tenant.csv) to climb to root and create a hidden account called troot.

Zero day at Cisco SD WAN exposes privilege escalation and the hidden troot account threatening the supply chain
Image generated with IA.

The operation presents a worrying pattern of good offensive practices: after changing administrative credentials to establish control, the attackers reversed passwords and removed traces - created files, changes in configuration - to make detection and forensic analysis difficult. This type of anti-forensic combined with the location of the engagement on edge devices (SD-WAN) complicates the visibility of the defenders, because these teams often lack EDR solutions and rich telemetry that allow to trace the lateral movement or the traffic interception this-west.

Beyond the specific impact on the network involved, the operation of SD-WAN drivers has systemic implications: an attacker with root on the controller can manipulate routes, intercept or redirect traffic between branches, hide persistence and obtain material for subsequent attacks against connected customers or suppliers. For network operators and safety equipment, this increases the risk to levels of supply chain and continuity of service.

The immediate and recommended actions for managers and response teams include: checking and immediately applying the patches and mitigations published by the supplier; rotating and strengthening administrative credentials; auditing / etc / passd and / etc / shadow files in search of hidden accounts such as troot; review recent changes in settings and backups to detect suspicious restorations; and keep forensic copies of configurations and disks before making any restitution that erases evidence. It is also critical to enable and centralize the remote log (syslog / SIEM) to retain events that attackers might try to remove locally.

On a broader operational level, the management and data plans of SD-WAN should be strictly segregated, administrative access should be limited by the principles of least privilege and role access controls, and demand strong authentication - ideally MFA - for netadmin accesses. The management of certificates and keys should include rotations, inventorship and detection of abnormal use; if there is evidence of certificate theft, proceed to revocation and replacement. Integrating file integrity monitoring and cryptographic verifications can help detect binary and configuration changes.

Zero day at Cisco SD WAN exposes privilege escalation and the hidden troot account threatening the supply chain
Image generated with IA.

Technically, teams should look for concrete prints: traces of CSV file uploads on management interfaces, altered time marks on configuration files, unauthorized peering events and scripts evidence that erases files. If commitment is detected, disconnect the affected device from the production network and work with a specialized IR team to preserve evidence, rebuild from clean images and communicate to suppliers and customers according to regulatory and reporting requirements.

This incident also underlines the need for greater transparency and coordination between suppliers and customers. Network device manufacturers should improve available telemetry, provide safe remote management mechanisms and speed up patches, while organizations should incorporate edge devices into their detection and response plans. For more technical context and updates see the Mandiant analysis on your blog and the CVE tab in the national vulnerability repository: Mandiant Blog and NVD - CVE-2026-20245.

In short, the early exploitation of CVE-2026-20245 is a reminder that network devices are privileged targets for advanced actors. Implementing patches, strengthening control and monitoring of SD-WAN management, and having robust forensic response procedures are not options: they are requirements to reduce the exposure window and limit the scope of future incidents.

Coverage

Related

More news on the same subject.