Security · 1h ago
Mandiant Details Cisco SD-WAN Zero-Day Exploit That Created Root Accounts
Hackers exploited CVE-2026-20245, a zero-day in Cisco Catalyst SD-WAN, to create rogue root accounts on targeted devices. Mandiant revealed the attack chain, which bypassed authentication and gained full system control. Cisco has released patches, but unpatched devices remain at risk.
Meridian48 take
The disclosure underscores how critical infrastructure vulnerabilities can be weaponized before patches are available, highlighting the need for proactive monitoring.
Read the full reporting
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access →
Bleeping Computer
cisco-sd-wanzero-day-exploit