Cisco SD-WAN Zero-Day Exploited for Months Before Patch

Google's Mandiant reveals months-long exploitation of a critical Cisco Catalyst SD-WAN vulnerability before the patch was released.

By Central
Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 was exploited by threat actors as a zero-day for months.
Highlights
  • CVE-2026-20245 allows authenticated attackers to execute arbitrary commands with root privileges on Cisco Catalyst SD-WAN Manager.
  • Attackers changed the default admin password during sessions to avoid detection, then restored it before logging out.
  • This zero-day is the seventh Cisco SD-WAN flaw uncovered in 2026, indicating a persistent campaign against SD-WAN infrastructure.

Google’s Mandiant team has revealed that a critical Cisco Catalyst SD-WAN vulnerability, tracked as CVE-2026-20245, was actively exploited as a zero-day for several months before Cisco disclosed it and released patches in early June. The flaw marks the seventh Cisco SD-WAN zero-day uncovered in 2026, underscoring the persistent targeting of network infrastructure appliances by sophisticated threat actors.

The Vulnerability: CVE-2026-20245

CVE-2026-20245 resides in the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager. The vulnerability allows an authenticated local attacker to execute arbitrary commands with root-level privileges by leveraging specially crafted files. Cisco disclosed the security hole in early June and issued patches approximately one week later, but by that time, attackers had already leveraged it in the wild for months.

Attack Timeline and Evasion Tactics

Mandiant’s investigation into the exploitation began in early 2026 after detecting an unidentified threat actor targeting SD-WAN infrastructure at a service provider. In March 2026, the attacker established initial access to an SD-WAN Manager instance via SSH using the built-in ‘vmanage-admin’ account. Once inside, they exploited CVE-2026-20245 to escalate privileges to root.

To minimize the chance of discovery, the threat actor changed the default admin account’s password during the session but restored it to its original value before logging out. “This activity was likely performed to reduce the probability of detection by an administrator trying to log into the device during day-to-day operations,” Mandiant explained. The vmanage-admin and admin accounts are default accounts on Cisco Catalyst SD-WAN controllers with different privilege levels, and neither normally possesses root shell access — making the privilege escalation step critical to the attack.

After achieving full root access, the attacker systematically deleted all files created during the intrusion, restored any altered system configurations, and executed a cleanup script designed to eliminate forensic evidence.

Broader Campaign Context

Mandiant noted that the same victim’s SD-WAN Manager systems had been targeted previously — possibly by the same or a different group — through exploitation of other zero-day vulnerabilities, specifically CVE-2026-20127 or CVE-2026-20182. These flaws were also zero-days at the time of their exploitation, suggesting a focused and persistent campaign against organizations using Cisco SD-WAN infrastructure.

“This campaign underscores the living off the edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters,” Mandiant stated. As organizations increasingly adopt software-defined networking, the orchestrators managing these environments become primary targets for attackers seeking broad network access and persistent footholds.

In a separate but related development, a cybersecurity firm has reported attacks exploiting CVE-2026-20230, a Cisco Unified CM vulnerability patched in early June. Cisco has stated it cannot confirm in-the-wild exploitation of that flaw as of late June.

What Affected Organizations Should Do Now

Organizations running Cisco Catalyst SD-WAN Manager should immediately apply the latest patches released by Cisco for CVE-2026-20245 and ensure all earlier SD-WAN zero-day patches, including those for CVE-2026-20127 and CVE-2026-20182, are deployed. Administrators should audit SSH access logs for any unusual activity involving default accounts such as vmanage-admin and admin, particularly sessions that involve password changes or command execution outside normal administrative tasks. Implementing multi-factor authentication for all administrative access and monitoring for unexpected configuration changes can help detect similar intrusion attempts. For organizations that have not yet patched, deploying a reputable network segmentation solution and enforcing strict access controls to SD-WAN management interfaces are critical interim measures.

Share This Article