Cisco SD-WAN Manager Vulnerability Exploited Two Months Before Disclosure (infosecurity-magazine.com)
- CVE-2026-20245 (CVSS 7.8) affects Cisco Catalyst SD-WAN Manager, Controller, Validator.
- Exploitation observed in March 2026, disclosed June 4, patched June 10.
- Attackers used unauthorized peering connections and stolen certificates for initial access.
- Two other zero-days (CVE-2026-20127, CVE-2026-20182) exploited since late 2025.
- Attackers deleted files and ran validation scripts to hide traces.
- Google highlighted 'living-off-the-edge' tactic targeting network appliances.
"A high-severity privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager was exploited by threat actors at least two months before Cisco disclosed it on June 4, 2026. Google's Mandiant reported finding exploitation as early as March 2026. The flaw allows authenticated local attackers to execute arbitrary commands as root via a crafted CSV upload. Cisco released patches starting June 10. Mandiant also observed earlier exploitation of two other zero-days (CVE-2026-20127, CVE-2026-20182) in late 2025 to January 2026, targeting SD-WAN infrastructure at a service provider. The campaign underscores the 'living-off-the-edge' paradigm where attackers compromise network appliances to bypass perimeter defenses."
no comments yet.