threat-intel
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
Critical
Summary
A zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN was exploited by an unknown threat actor, gaining root access to a communications service provider’s network. The attack involved anti-forensic techniques, multiple phases of unauthorized activity, and the use of crafted CSV files to escalate privileges. This highlights the risk posed by unpatched edge devices lacking telemetry.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
