A zero-day vulnerability in Cisco Catalyst SD-WAN allowed attackers to establish persistent root-level access, with Mandiant now shedding light on the exploitation mechanics.
Summary
- CVE-2026-20245 is a zero-day vulnerability affecting Cisco Catalyst SD-WAN devices that was actively exploited before a patch was available.
- Attackers leveraged the flaw to create unauthorised root accounts, granting them full control over targeted devices.
- Mandiant conducted the analysis and has disclosed further technical details on how the exploitation chain was executed.
- Corroborating reporting from The Hacker News confirms the scope and severity of the zero-day activity.
- Organisations running Cisco Catalyst SD-WAN infrastructure should treat this as a priority remediation item.
What Happened
Mandiant has published new technical detail on attacks exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20245. The flaw was used in active campaigns to create rogue root accounts on affected devices, giving threat actors persistent, elevated access to network infrastructure that sits at the heart of enterprise connectivity.
The Exploitation Mechanics
According to the source material, attackers were able to exploit CVE-2026-20245 to gain root access on targeted Cisco Catalyst SD-WAN devices. The ability to establish root-level accounts through a zero-day — that is, before any vendor patch existed — represents a significant window of exposure for any organisation relying on this technology. The Hacker News corroborates this account, confirming the zero-day nature of the attacks and the root access outcome.
Why SD-WAN Is a High-Value Target
SD-WAN appliances occupy a privileged position in enterprise network architecture. They sit at the boundary of branch and cloud connectivity, often handling traffic routing decisions across an organisation’s entire wide-area network. Compromise at this layer can give an adversary broad visibility into network flows, the ability to intercept or redirect traffic, and a persistent foothold that may survive standard endpoint detection. Root-level access amplifies all of these risks considerably, as it removes most practical limitations on what an attacker can do once inside the device.
Limits of What Is Known
The source material does not specify which threat actor or actors are responsible for the zero-day exploitation, nor does it provide detail on the number of organisations affected or the geographic scope of the campaign. The specific technical steps within the exploitation chain beyond the creation of rogue root accounts are also not fully described in available public reporting. Security teams should monitor Mandiant and Cisco’s official advisories for further attribution or indicator releases as the investigation matures.
Patch and Advisory Status
The vulnerability is designated CVE-2026-20245 and relates specifically to Cisco Catalyst SD-WAN. Organisations should consult Cisco’s official security advisories directly to confirm whether patches are available, which product versions and software releases are affected, and whether any workarounds have been recommended. Given that this was exploited as a zero-day, the priority should be confirming patch availability and applying it at the earliest possible opportunity.
Why it matters
For a CISO, a zero-day in SD-WAN infrastructure is a particularly uncomfortable risk scenario. Unlike an endpoint compromise, a rooted SD-WAN device sits upstream of many security controls and can expose traffic, credentials, and network topology to an adversary in ways that are difficult to detect through conventional monitoring. The creation of rogue root accounts also implies persistence — meaning that even if the initial vulnerability is patched, affected devices may remain compromised unless thoroughly investigated and rebuilt. Any organisation running Cisco Catalyst SD-WAN should treat this as an urgent matter: verify patch status, hunt for indicators of compromise on affected appliances, and review whether any devices may have been accessed by unauthorised accounts. Given that the exploitation preceded patch availability, assuming no exposure without active investigation would be unwise.
What to do now
- Consult Cisco’s official security advisory for CVE-2026-20245 to determine which Catalyst SD-WAN versions are affected and whether a patch is currently available.
- Apply any available patches or vendor-recommended mitigations to Cisco Catalyst SD-WAN devices as a priority.
- Audit all user and root accounts on Cisco Catalyst SD-WAN devices for any that are unrecognised or unauthorised.
- Review device logs and configurations on Catalyst SD-WAN appliances for signs of tampering or unexpected changes consistent with post-exploitation activity.
- Monitor Mandiant and Cisco advisories for any published indicators of compromise or further technical detail that can support threat hunting efforts.
- Consider isolating or increasing monitoring on Catalyst SD-WAN devices until patching and investigation are complete.
