Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access

Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access

Posted on June 25, 2026 By CWS

An unknown threat actor has taken advantage of a significant security flaw in Cisco Catalyst SD-WAN, as revealed by Mandiant, a cybersecurity firm owned by Google. The vulnerability, known as CVE-2026-20245, was exploited as a zero-day, with the breach occurring at least two months prior to its public disclosure.

Understanding the Vulnerability

The flaw, assigned a CVSS score of 7.8, allows authenticated local attackers to run arbitrary commands with elevated privileges. This is achieved by providing a specially crafted file to the vulnerable system, exploiting its inadequate validation of user input. Cisco acknowledged the breach earlier this month, noting that attackers needed netadmin privileges to successfully exploit the vulnerability.

Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan from Mandiant highlighted that the threat actor used anti-forensic techniques throughout the attack, selectively deleting and restoring system files to maintain stealth. The attack targeted a communications service provider, enabling the attackers to elevate a compromised admin account to root-level access.

Timeline of the Attack

The breach involved two phases of unauthorized activity: the first between late 2025 and January 2026, and the second in March 2026. While it remains uncertain if the same actor was responsible for both, the initial wave of the attack exploited authentication bypass flaws in Cisco Catalyst SD-WAN controllers (CVE-2026-20127 or CVE-2026-20182), both undisclosed zero-days at the time.

In March 2026, a second series of rogue connections targeted updated software patched against CVE-2026-20127. Cisco confirmed these connections did not exploit CVE-2026-20182, suggesting the attacker might have used stolen certificates from a prior breach to gain initial access. The intruder then uploaded a malicious CSV file, leveraging CVE-2026-20245 to escalate privileges and create a root-level user account.

Implications and Future Concerns

The attackers took extensive measures to erase their digital footprint by deleting files and reverting configuration changes. This sophisticated approach complicates defenders’ efforts to evaluate the full scope of the breach. According to Austin Larsen from Google’s Threat Intelligence Group, the attackers altered admin credentials and exfiltrated configuration data, then restored the original password to avoid detection.

This incident underscores the persistent threat of zero-day exploits against network devices lacking deep forensic capabilities. Charles Carmakal, CTO of Mandiant Consulting, noted the trend of cyber adversaries targeting network devices, which often do not support Endpoint Detection and Response (EDR) solutions. This ongoing challenge emphasizes the need for enhanced security measures across network infrastructures.

The Hacker News Tags:Cisco, Cybersecurity, Exploit, Google, Mandiant, network security, root access, SD-WAN, Security, threat intelligence, Vulnerability, zero-day

Post navigation

Previous Post: Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
Next Post: Cisco SD-WAN Exploit Exposed Months Before Patch

Related Posts

Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls The Hacker News
Urgent 12-Hour Patch Rule Set by CERT-In for AI Threats Urgent 12-Hour Patch Rule Set by CERT-In for AI Threats The Hacker News
Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics The Hacker News
Critical SolarWinds Vulnerability Listed as Actively Exploited Critical SolarWinds Vulnerability Listed as Actively Exploited The Hacker News
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells The Hacker News
CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco SD-WAN Exploit Exposed Months Before Patch
  • Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access
  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft
  • Exploit Released for Microsoft Exchange Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco SD-WAN Exploit Exposed Months Before Patch
  • Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access
  • Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
  • Mass Exploit Targets Laravel Livewire Apps for Credential Theft
  • Exploit Released for Microsoft Exchange Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark