Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Manager Flaw Exploited for Root Access

Cisco SD-WAN Manager Flaw Exploited for Root Access

Posted on June 24, 2026 By CWS

A recent cybersecurity incident has revealed a significant vulnerability in Cisco Catalyst SD-WAN Manager, exploited by a sophisticated hacking group. The attackers targeted a service provider’s SD-WAN infrastructure by leveraging a zero-day privilege escalation flaw, identified as CVE-2026-20245, which carries a severity score of 7.8 on the CVSS scale. This breach enabled them to escalate privileges from an administrative account to full root access, posing a grave security risk.

Understanding the Vulnerability

The vulnerability, CVE-2026-20245, is located in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controllers. It falls under the category of CWE-116, which deals with improper encoding or escaping of output. The flaw arises from inadequate validation in the file upload feature, allowing attackers with netadmin-level privileges to upload malicious CSV files. These files can trigger command injection, enabling execution of arbitrary commands with root privileges.

This issue impacts all deployment scenarios, including On-Prem, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP government environments. The exploitation process unfolded in two phases: initially, unauthorized connections were established, exploiting other vulnerabilities like CVE-2026-20127 and CVE-2026-20182. These allowed attackers to gain administrative privileges without detection.

Exploit Techniques and Attack Details

From March 2026, the attackers renewed their efforts by establishing new rogue connections and using default credentials to access the SD-WAN Manager via SSH. They altered the admin account password and accessed the web interface to extract sensitive configuration data. Notably, the password was restored afterward to prevent suspicion.

The core of their strategy involved uploading a file named evil_tenant.csv during an SSH session. This file’s payload modified critical system files like /etc/passwd and /etc/shadow, creating a new user with root-level privileges. The attackers used this account to gain complete control over the management plane, followed by a thorough cleanup to erase any forensic evidence.

Recommended Mitigation Steps

In response to this threat, organizations using Cisco Catalyst SD-WAN Manager should take immediate action. They are advised to upgrade to the latest software versions, such as 20.9.9.2 and higher, which contain necessary security patches. Additionally, conducting log reviews and monitoring for suspicious activity is crucial.

Organizations should follow Cisco’s guidelines for securing their SD-WAN environments, including the administration of strict access controls and regular security sweeps. Contacting Cisco TAC is essential if any signs of compromise are detected, to ensure swift and effective remediation.

This incident underscores the increasing trend of zero-day exploits targeting network appliances. It highlights the need for robust security measures and the treatment of management planes as critical attack surfaces. Continuous monitoring and proactive patch management remain vital to defend against such evolving cyber threats.

Cyber Security News Tags:Cisco, cloud security, CVE-2026-20245, cyber threat, Cybersecurity, Hacking, IT infrastructure, IT security, network appliances, network security, patch management, root access, SD-WAN, Vulnerability, zero-day

Post navigation

Previous Post: Ubiquiti Device Flaws Targeted by Cyber Threats
Next Post: Amadey and StealC Takedown Recovers 27M Stolen Records

Related Posts

APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks Cyber Security News
Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups Cyber Security News
Microsoft Rolls Out Windows 11 Cumulative Updates KB5058411 and KB5058405 Microsoft Rolls Out Windows 11 Cumulative Updates KB5058411 and KB5058405 Cyber Security News
Apache Tomcat and Camel Vulnerabilities Actively Exploited in The Wild Apache Tomcat and Camel Vulnerabilities Actively Exploited in The Wild Cyber Security News
Fake AI Installers Exploit Users with Malware Fake AI Installers Exploit Users with Malware Cyber Security News
Researchers Uncover the Strong Links Between Maverick and Coyote Banking Malwares Researchers Uncover the Strong Links Between Maverick and Coyote Banking Malwares Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • The Importance of Context in Agentic AI Security
  • CISA Alerts on Critical Lantronix EDS5000 Vulnerability
  • EvilTokens Exposes Browser-Level Phishing Gaps
  • Exploring AI Agent Vulnerabilities and Defense Strategies
  • Amadey and StealC Takedown Recovers 27M Stolen Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • The Importance of Context in Agentic AI Security
  • CISA Alerts on Critical Lantronix EDS5000 Vulnerability
  • EvilTokens Exposes Browser-Level Phishing Gaps
  • Exploring AI Agent Vulnerabilities and Defense Strategies
  • Amadey and StealC Takedown Recovers 27M Stolen Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark