vulnerability
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
High
Summary
A Mandiant report details how attackers exploited a zero-day vulnerability (CVE-2026-20245) in Cisco SD-WAN Manager, Controller, and Validator software to gain root access on targeted devices. The attackers initially gained access through unauthorized peering connections and then leveraged the command injection flaw to escalate privileges, modify configurations, and erase forensic traces. This highlights the importance of patching vulnerabilities and monitoring network connections for suspicious activity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data