Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Manager Flaw Exploited for Root Access

Cisco SD-WAN Manager Flaw Exploited for Root Access

Posted on June 24, 2026 By CWS

A recent cybersecurity incident has revealed a significant vulnerability in Cisco Catalyst SD-WAN Manager, exploited by a sophisticated hacking group. The attackers targeted a service provider’s SD-WAN infrastructure by leveraging a zero-day privilege escalation flaw, identified as CVE-2026-20245, which carries a severity score of 7.8 on the CVSS scale. This breach enabled them to escalate privileges from an administrative account to full root access, posing a grave security risk.

Understanding the Vulnerability

The vulnerability, CVE-2026-20245, is located in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controllers. It falls under the category of CWE-116, which deals with improper encoding or escaping of output. The flaw arises from inadequate validation in the file upload feature, allowing attackers with netadmin-level privileges to upload malicious CSV files. These files can trigger command injection, enabling execution of arbitrary commands with root privileges.

This issue impacts all deployment scenarios, including On-Prem, Cisco SD-WAN Cloud, Cloud-Pro, and FedRAMP government environments. The exploitation process unfolded in two phases: initially, unauthorized connections were established, exploiting other vulnerabilities like CVE-2026-20127 and CVE-2026-20182. These allowed attackers to gain administrative privileges without detection.

Exploit Techniques and Attack Details

From March 2026, the attackers renewed their efforts by establishing new rogue connections and using default credentials to access the SD-WAN Manager via SSH. They altered the admin account password and accessed the web interface to extract sensitive configuration data. Notably, the password was restored afterward to prevent suspicion.

The core of their strategy involved uploading a file named evil_tenant.csv during an SSH session. This file’s payload modified critical system files like /etc/passwd and /etc/shadow, creating a new user with root-level privileges. The attackers used this account to gain complete control over the management plane, followed by a thorough cleanup to erase any forensic evidence.

Recommended Mitigation Steps

In response to this threat, organizations using Cisco Catalyst SD-WAN Manager should take immediate action. They are advised to upgrade to the latest software versions, such as 20.9.9.2 and higher, which contain necessary security patches. Additionally, conducting log reviews and monitoring for suspicious activity is crucial.

Organizations should follow Cisco’s guidelines for securing their SD-WAN environments, including the administration of strict access controls and regular security sweeps. Contacting Cisco TAC is essential if any signs of compromise are detected, to ensure swift and effective remediation.

This incident underscores the increasing trend of zero-day exploits targeting network appliances. It highlights the need for robust security measures and the treatment of management planes as critical attack surfaces. Continuous monitoring and proactive patch management remain vital to defend against such evolving cyber threats.

Cyber Security News Tags:Cisco, cloud security, CVE-2026-20245, cyber threat, Cybersecurity, Hacking, IT infrastructure, IT security, network appliances, network security, patch management, root access, SD-WAN, Vulnerability, zero-day

Post navigation

Previous Post: Ubiquiti Device Flaws Targeted by Cyber Threats
Next Post: Amadey and StealC Takedown Recovers 27M Stolen Records

Related Posts

New Cyber Attack Weaponizes DeskSoft to Deploy Malware Leveraging RDP Access to Execute Commands New Cyber Attack Weaponizes DeskSoft to Deploy Malware Leveraging RDP Access to Execute Commands Cyber Security News
UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia Cyber Security News
Researchers Manipulate Stolen Data to Corrupt AI Models and Generate Inaccurate Outputs Researchers Manipulate Stolen Data to Corrupt AI Models and Generate Inaccurate Outputs Cyber Security News
Chinese Hackers Breach Oil Sector via Microsoft Exchange Chinese Hackers Breach Oil Sector via Microsoft Exchange Cyber Security News
LiteLLM Vulnerability Enables Remote Code Execution LiteLLM Vulnerability Enables Remote Code Execution Cyber Security News
Triad Nexus Returns with Advanced Scam Infrastructure Triad Nexus Returns with Advanced Scam Infrastructure Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exploring AI Agent Vulnerabilities and Defense Strategies
  • Amadey and StealC Takedown Recovers 27M Stolen Records
  • Cisco SD-WAN Manager Flaw Exploited for Root Access
  • Ubiquiti Device Flaws Targeted by Cyber Threats
  • Global Operation Targets Major Cybercrime Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exploring AI Agent Vulnerabilities and Defense Strategies
  • Amadey and StealC Takedown Recovers 27M Stolen Records
  • Cisco SD-WAN Manager Flaw Exploited for Root Access
  • Ubiquiti Device Flaws Targeted by Cyber Threats
  • Global Operation Targets Major Cybercrime Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark