Google's Mandiant team revealed that attackers exploited a critical privilege escalation flaw in Cisco Catalyst SD-WAN (CVE-2026-20245) as early as March 2026, roughly two months before Cisco publicly disclosed it in June. The vulnerability, stemming from insufficient input validation in the SD-WAN Controller CLI, allowed authenticated attackers to execute arbitrary commands as root. Initial access was achieved via rogue peering connections, likely by chaining two previously disclosed authentication bypass zero-days (CVE-2026-20182 and CVE-2026-20127). The threat actor conducted extensive anti-forensic cleanup after achieving their objectives. CISA added the flaw to its known exploited vulnerabilities catalog and set a June 23 deadline for federal agencies to patch. Mandiant highlighted growing attacker interest in network devices due to their limited forensic visibility and central control plane access.