Security · 2h ago
Cisco SD-WAN Zero-Day Exploited for Root Access Before Disclosure
Mandiant discovered that an unknown threat actor exploited CVE-2026-20245, a high-severity Cisco Catalyst SD-WAN flaw, as a zero-day for at least two months before public disclosure. The vulnerability (CVSS 7.8) allows authenticated local attackers to execute arbitrary commands with elevated privileges. Cisco has since released a patch.
Meridian48 take
The two-month gap between exploitation and disclosure underscores the challenge of detecting zero-days in enterprise networking gear, especially when attackers already have authenticated access.
Read the full reporting
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access →
The Hacker News
ciscozero-day