Briefing

Cisco Catalyst SD‑WAN Zero‑Day Exploited Before Public Disclosure

security
by [email protected] (The Hacker News) · CVE-2026-20245

Patch Cisco Catalyst SD‑WAN firmware to the latest version that fixes CVE‑2026‑20245.

What to do now

Patch the Cisco Catalyst SD‑WAN firmware to the latest version that contains the fix for CVE‑2026‑20245.

Summary

An unknown threat actor exploited a recently disclosed high‑severity security flaw in Cisco Catalyst SD‑WAN before it was publicly disclosed, according to new findings from Google‑owned Mandiant.

The vulnerability, identified as CVE‑2026‑20245, carries a CVSS score of 7.8 and allows an authenticated local attacker to execute arbitrary commands with elevated privileges. The flaw was actively exploited at least two months prior to its public disclosure, demonstrating a zero‑day window that could have impacted thousands of SD‑WAN deployments. Mandiant’s investigation traced the exploitation to a sophisticated actor that leveraged the flaw to gain privileged access within the network fabric. Cisco has released a patch that mitigates the issue by tightening privilege checks on command execution. Network administrators should verify that their SD‑WAN firmware is updated to the latest version and monitor logs for anomalous command activity. Failure to patch could leave the network vulnerable to remote code execution and potential lateral movement by attackers.

Key changes

  • CVE‑2026‑20245 identified
  • CVSS score 7.8
  • Authenticated local attacker can execute arbitrary commands with elevated privileges
  • Exploited at least two months before public disclosure
  • Mandiant investigation revealed sophisticated actor
  • Cisco released patch tightening privilege checks
  • Firmware update required
  • Zero‑day exploitation window demonstrated

Affects

none

Source angles · 2 perspectives

The Hacker News
Independent angle

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

Open
Bleeping Computer
Independent angle

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting