Google's Mandiant team revealed that attackers exploited a critical privilege escalation flaw in Cisco Catalyst SD-WAN (CVE-2026-20245) as early as March 2026, roughly two months before Cisco publicly disclosed it in June. The vulnerability, stemming from insufficient input validation in the SD-WAN Controller CLI, allowed authenticated attackers to execute arbitrary commands as root. Initial access was achieved via rogue peering connections, likely by chaining two previously disclosed authentication bypass zero-days (CVE-2026-20182 and CVE-2026-20127). The threat actor conducted extensive anti-forensic cleanup after achieving their objectives. CISA added the flaw to its known exploited vulnerabilities catalog and set a June 23 deadline for federal agencies to patch. Mandiant highlighted growing attacker interest in network devices due to their limited forensic visibility and central control plane access.

4m read timeFrom darkreading.com
Post cover image
Table of contents
Privilege Escalation FlawInitial Access Via Rogue PeeringExtensive Anti-ForensicsA Target of Growing Interest
141 Impressions