The images in this article were generated with artificial intelligence. How we publish
A recent report by Mandiant, the Google-owned response and intelligence unit, reveals that an unknown actor exploded as zero-day a high severity failure in Cisco Catalyst SD-WAN at least two months before its public disclosure. Vulnerability, recorded as CVE-2026-20245(CVSS 7.8), allows an authenticated local attacker to run commands with high privileges by loading a specially designed file that takes advantage of insufficient user input validation.
The findings describe a campaign directed against a communications service provider in which two separate waves of unauthorized activity were detected: one between the end of 2025 and January 2026, and one in March 2026. During the first stage the attackers probably abused authentication vulnerabilities not yet disclosed (CVE-2026-20127 or CVE-2026-20182) to create rogue peering connections; in the second stage, after updating the software of a device, they did not use those same faults but could resort to stolen certificates and the exploitation of CVE-2026-20245 by raising a malicious CSV (evil _ tenant.csv) to climb to root and create a hidden account called troot.

The operation presents a worrying pattern of good offensive practices: after changing administrative credentials to establish control, the attackers reversed passwords and removed traces - created files, changes in configuration - to make detection and forensic analysis difficult. This type of anti-forensic combined with the location of the engagement on edge devices (SD-WAN) complicates the visibility of the defenders, because these teams often lack EDR solutions and rich telemetry that allow to trace the lateral movement or the traffic interception this-west.
Beyond the specific impact on the network involved, the operation of SD-WAN drivers has systemic implications: an attacker with root on the controller can manipulate routes, intercept or redirect traffic between branches, hide persistence and obtain material for subsequent attacks against connected customers or suppliers. For network operators and safety equipment, this increases the risk to levels of supply chain and continuity of service.
The immediate and recommended actions for managers and response teams include: checking and immediately applying the patches and mitigations published by the supplier; rotating and strengthening administrative credentials; auditing / etc / passd and / etc / shadow files in search of hidden accounts such as troot; review recent changes in settings and backups to detect suspicious restorations; and keep forensic copies of configurations and disks before making any restitution that erases evidence. It is also critical to enable and centralize the remote log (syslog / SIEM) to retain events that attackers might try to remove locally.
On a broader operational level, the management and data plans of SD-WAN should be strictly segregated, administrative access should be limited by the principles of least privilege and role access controls, and demand strong authentication - ideally MFA - for netadmin accesses. The management of certificates and keys should include rotations, inventorship and detection of abnormal use; if there is evidence of certificate theft, proceed to revocation and replacement. Integrating file integrity monitoring and cryptographic verifications can help detect binary and configuration changes.

Technically, teams should look for concrete prints: traces of CSV file uploads on management interfaces, altered time marks on configuration files, unauthorized peering events and scripts evidence that erases files. If commitment is detected, disconnect the affected device from the production network and work with a specialized IR team to preserve evidence, rebuild from clean images and communicate to suppliers and customers according to regulatory and reporting requirements.
This incident also underlines the need for greater transparency and coordination between suppliers and customers. Network device manufacturers should improve available telemetry, provide safe remote management mechanisms and speed up patches, while organizations should incorporate edge devices into their detection and response plans. For more technical context and updates see the Mandiant analysis on your blog and the CVE tab in the national vulnerability repository: Mandiant Blog and NVD - CVE-2026-20245.
In short, the early exploitation of CVE-2026-20245 is a reminder that network devices are privileged targets for advanced actors. Implementing patches, strengthening control and monitoring of SD-WAN management, and having robust forensic response procedures are not options: they are requirements to reduce the exposure window and limit the scope of future incidents.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...