Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access

Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access

Posted on June 25, 2026 By CWS

An unknown threat actor has taken advantage of a significant security flaw in Cisco Catalyst SD-WAN, as revealed by Mandiant, a cybersecurity firm owned by Google. The vulnerability, known as CVE-2026-20245, was exploited as a zero-day, with the breach occurring at least two months prior to its public disclosure.

Understanding the Vulnerability

The flaw, assigned a CVSS score of 7.8, allows authenticated local attackers to run arbitrary commands with elevated privileges. This is achieved by providing a specially crafted file to the vulnerable system, exploiting its inadequate validation of user input. Cisco acknowledged the breach earlier this month, noting that attackers needed netadmin privileges to successfully exploit the vulnerability.

Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan from Mandiant highlighted that the threat actor used anti-forensic techniques throughout the attack, selectively deleting and restoring system files to maintain stealth. The attack targeted a communications service provider, enabling the attackers to elevate a compromised admin account to root-level access.

Timeline of the Attack

The breach involved two phases of unauthorized activity: the first between late 2025 and January 2026, and the second in March 2026. While it remains uncertain if the same actor was responsible for both, the initial wave of the attack exploited authentication bypass flaws in Cisco Catalyst SD-WAN controllers (CVE-2026-20127 or CVE-2026-20182), both undisclosed zero-days at the time.

In March 2026, a second series of rogue connections targeted updated software patched against CVE-2026-20127. Cisco confirmed these connections did not exploit CVE-2026-20182, suggesting the attacker might have used stolen certificates from a prior breach to gain initial access. The intruder then uploaded a malicious CSV file, leveraging CVE-2026-20245 to escalate privileges and create a root-level user account.

Implications and Future Concerns

The attackers took extensive measures to erase their digital footprint by deleting files and reverting configuration changes. This sophisticated approach complicates defenders’ efforts to evaluate the full scope of the breach. According to Austin Larsen from Google’s Threat Intelligence Group, the attackers altered admin credentials and exfiltrated configuration data, then restored the original password to avoid detection.

This incident underscores the persistent threat of zero-day exploits against network devices lacking deep forensic capabilities. Charles Carmakal, CTO of Mandiant Consulting, noted the trend of cyber adversaries targeting network devices, which often do not support Endpoint Detection and Response (EDR) solutions. This ongoing challenge emphasizes the need for enhanced security measures across network infrastructures.

The Hacker News Tags:Cisco, Cybersecurity, Exploit, Google, Mandiant, network security, root access, SD-WAN, Security, threat intelligence, Vulnerability, zero-day

Post navigation

Previous Post: Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
Next Post: Cisco SD-WAN Exploit Exposed Months Before Patch

Related Posts

Google Cloud Vertex AI SDK Flaw Exposed Model Uploads Google Cloud Vertex AI SDK Flaw Exposed Model Uploads The Hacker News
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post Approval The Hacker News
New HTTP/2 Bomb Exploit Threatens Major Web Servers New HTTP/2 Bomb Exploit Threatens Major Web Servers The Hacker News
ScarCruft Exploits Zoho WorkDrive for Air-Gapped Network Breach ScarCruft Exploits Zoho WorkDrive for Air-Gapped Network Breach The Hacker News
Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets The Hacker News
Hackers Target Critical Quest KACE SMA Vulnerability Hackers Target Critical Quest KACE SMA Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Chrome Update Fixes 18 Critical Security Flaws
  • Cisco SD-WAN Exploit Exposed Months Before Patch
  • Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access
  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Chrome Update Fixes 18 Critical Security Flaws
  • Cisco SD-WAN Exploit Exposed Months Before Patch
  • Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access
  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark