Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
Attackers exploited a critical vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20245) approximately two months before Cisco publicly disclosed it. The vulnerability, stemming from insufficient input validation, allowed attackers to escalate privileges to root-level access via rogue peering connections, initially targeting a service provider. The attackers employed extensive anti-forensic techniques after gaining access, and the vulnerability was linked to the UAT-8616 threat actor, who had been exploiting related zero-days since 2023, highlighting a growing trend of targeting network devices for initial access.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
