Cisco Catalyst SD-WAN Bug Hit as Zero-Day Months Before Disclosure
Mandiant says an unidentified actor exploited CVE-2026-20245 for at least two months before Cisco's public advisory, gaining root on affected appliances.

Key points
- An unknown attacker exploited CVE-2026-20245 as a zero-day for at least two months before Cisco disclosed it.
- The flaw carries a CVSS score of 7.8 and lets an authenticated local attacker run commands with elevated privileges, reaching root on the device.
- Mandiant caught the activity during incident response but has not named a threat actor.
- Cisco's fixed software is available; administrators should pull affected version ranges from the Cisco Security Advisories portal.
- Patching closes the entry point but won't remove an operator already present on the appliance.
An unknown attacker used a Cisco Catalyst SD-WAN zero-day for at least eight weeks before the vendor went public, according to incident-response telemetry from Mandiant, owned by Google.
The vulnerability is tracked as CVE-2026-20245, CVSS 7.8. An authenticated local attacker can execute arbitrary commands with elevated privileges, which in practice means root on network infrastructure sitting at the edge of enterprise WANs. We've followed this CVE since it surfaced: our 6 June story "Cisco SD-WAN Manager Bug Under Active Exploit, No Fix Yet" reported exploitation in the wild while customers were still waiting on a patch.
Why does the authentication requirement matter?
The local-auth prerequisite softens the CVSS number but doesn't neutralise the risk. Operators routinely chain that kind of requirement with credential theft or a separate web-management flaw to reach the needed shell. Mandiant's findings suggest whoever was in here had a reliable path to that first stage.
Catalyst SD-WAN gear is exactly the asset espionage crews and access brokers prize: persistent, rarely rebooted, seldom covered by endpoint detection tools, and capable of brokering traffic between branch offices and cloud. Root on the box is root on the routing fabric. Two months of quiet exploitation on that kind of hardware is not a smash-and-grab.
Should you worry about appliances that were already exposed?
Yes, if they were internet-reachable or accessible from a compromised management segment during the exploitation window. Patching closes the door. It doesn't evict anyone already inside.
Hunt for anomalous local account activity, unexpected privilege changes, and new scheduled-task or init-script persistence on the appliances. Operators who burn a zero-day for two months without detection tend to leave something durable behind. Rotate credentials for any account that could authenticate locally to the device, covering both direct logins and any network authentication service backing admin roles, and compare current configs against a known-good baseline.
What don't we know yet?
Mandiant hasn't disclosed victim count, sector concentration, or geography. Cisco hasn't said how it learned of the flaw, whether through a customer incident or an internal find. Neither party has named a threat actor.
The pattern is familiar: edge device, authenticated remote-code-execution, quiet exploitation, attribution pending. Network appliances buy operators dwell time that workstation implants no longer do, and the industry keeps relearning that lesson one advisory at a time.
Threat Vectr has reached out to Cisco for clarification on the exploitation timeline and will update if the company responds.



