Cisco Catalyst SD-WAN Bug Hit as Zero-Day Months Before Disclosure
Mandiant says an unidentified actor exploited CVE-2026-20245 for at least two months before Cisco's public advisory, gaining root on affected appliances.

An unknown attacker burned a Cisco Catalyst SD-WAN zero-day for at least two months before the vendor disclosed it, according to incident-response telemetry from Mandiant.
The bug is tracked as CVE-2026-20245 and carries a CVSS score of 7.8. It allows an authenticated local attacker to run arbitrary commands with elevated privileges on the device. In practice, that means root on a piece of network infrastructure that sits at the edge of enterprise WANs.
Mandiant, owned by Google, says it caught the activity during incident response and traced exploitation back to a window predating Cisco's advisory by roughly eight weeks. The firm has not publicly attributed the intrusions to a named group.
That is the awkward part. Catalyst SD-WAN gear is exactly the kind of asset that espionage crews and access brokers prize: persistent, rarely rebooted, often unmonitored by EDR, and capable of brokering traffic between branch offices and cloud. Root on the box is root on the routing fabric.
The authentication requirement softens the CVSS number but does not neutralise it. Local-auth-required bugs on network appliances are routinely chained with credential theft, stale service accounts, or a separate web-management flaw to reach the prerequisite shell. Mandiant's findings suggest the operator had a reliable path to that first stage.
Cisco's fixed software is available through the vendor's standard channels, and administrators should pull the current advisory directly from the Cisco Security Advisories portal for affected version ranges.
A few practical points for defenders.
First, assume pre-patch compromise on any Catalyst SD-WAN appliance that was internet-exposed or reachable from a compromised management segment during the suspected exploitation window. Patching closes the door. It does not evict anyone already inside.
Second, hunt for anomalous local account usage, unexpected privilege escalations, and new cron or systemd persistence on the appliances themselves. Zero-day operators who burn a bug for two months without detection tend to plant something durable.
Third, rotate credentials for any account that could authenticate locally to the device, including TACACS and RADIUS-backed admin roles, and review configuration diffs against a known-good baseline.
Mandiant has not disclosed victim count, sector concentration, or geography. Cisco has not said how it became aware of the flaw, whether through a customer incident, an internal find, or a third-party report. Neither party has named a threat actor.
The disclosure pattern fits a now-familiar shape: edge device, authenticated RCE, quiet exploitation, attribution pending. Operators have learned that network appliances buy them dwell time that workstation implants no longer do.
Threat Vectr has reached out to Cisco for clarification on the exploitation timeline and will update if the company responds.



