Mandiant details Cisco SD-WAN zero-day exploitation for root access

Mandiant has exposed how attackers exploited a zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN to create rogue root accounts on devices, raising serious security concerns. This vulnerability enables full control of targeted network appliances, potentially impacting enterprise operations.

Why it matters

Understanding this exploitation helps defenders prevent critical intrusions in widely deployed SD-WAN infrastructure.

SOC impact

Understanding this exploitation helps defenders prevent critical intrusions in widely deployed SD-WAN infrastructure.

Recommended actions

  1. Review the original source and determine whether the affected technology is present in your environment.
  2. Monitor relevant telemetry for indicators or behaviors associated with this issue.
  3. Document exposure, validation steps, and remediation status.

Executive Summary

Mandiant has exposed how attackers exploited a zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN to create rogue root accounts on devices, raising serious security concerns. This vulnerability enables full control of targeted network appliances, potentially impacting enterprise operations.

What SOC Teams Should Validate

  • Review the original source and determine whether the affected technology is present in your environment.
  • Monitor relevant telemetry for indicators or behaviors associated with this issue.
  • Document exposure, validation steps, and remediation status.

Why It Matters

Understanding this exploitation helps defenders prevent critical intrusions in widely deployed SD-WAN infrastructure.

Source