techjacksolutions.com • 4h
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited for Root Access
In early 2026, attackers leveraged rogue peering to gain SSH access to a Cisco Catalyst SD-WAN Manager using the default vmanage-admin account, then exploited CVE-2026-20245—a local privilege‑escalation flaw in the SD‑WAN Manager CLI—to upload a malicious CSV file (evil_tenant.csv) that added a hidden troot account to /etc/passwd and /etc/shadow, achieving root. The incident, observed by Mandiant and Google GTIG, resulted in management‑plane compromise, configuration exfiltration, and anti‑forensic cleanup, highlighting SD‑WAN controllers as high‑value targets for persistent privileged access.
Links:techjacksolutions.com, Tenable, Sec, Labs, cyberscoop.com, thehackernews.com, Nvd, Greenbone •