Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access

Cisco SD-WAN Zero-Day Vulnerability Exploited for Root Access

Posted on June 25, 2026 By CWS

An unknown threat actor has taken advantage of a significant security flaw in Cisco Catalyst SD-WAN, as revealed by Mandiant, a cybersecurity firm owned by Google. The vulnerability, known as CVE-2026-20245, was exploited as a zero-day, with the breach occurring at least two months prior to its public disclosure.

Understanding the Vulnerability

The flaw, assigned a CVSS score of 7.8, allows authenticated local attackers to run arbitrary commands with elevated privileges. This is achieved by providing a specially crafted file to the vulnerable system, exploiting its inadequate validation of user input. Cisco acknowledged the breach earlier this month, noting that attackers needed netadmin privileges to successfully exploit the vulnerability.

Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan from Mandiant highlighted that the threat actor used anti-forensic techniques throughout the attack, selectively deleting and restoring system files to maintain stealth. The attack targeted a communications service provider, enabling the attackers to elevate a compromised admin account to root-level access.

Timeline of the Attack

The breach involved two phases of unauthorized activity: the first between late 2025 and January 2026, and the second in March 2026. While it remains uncertain if the same actor was responsible for both, the initial wave of the attack exploited authentication bypass flaws in Cisco Catalyst SD-WAN controllers (CVE-2026-20127 or CVE-2026-20182), both undisclosed zero-days at the time.

In March 2026, a second series of rogue connections targeted updated software patched against CVE-2026-20127. Cisco confirmed these connections did not exploit CVE-2026-20182, suggesting the attacker might have used stolen certificates from a prior breach to gain initial access. The intruder then uploaded a malicious CSV file, leveraging CVE-2026-20245 to escalate privileges and create a root-level user account.

Implications and Future Concerns

The attackers took extensive measures to erase their digital footprint by deleting files and reverting configuration changes. This sophisticated approach complicates defenders’ efforts to evaluate the full scope of the breach. According to Austin Larsen from Google’s Threat Intelligence Group, the attackers altered admin credentials and exfiltrated configuration data, then restored the original password to avoid detection.

This incident underscores the persistent threat of zero-day exploits against network devices lacking deep forensic capabilities. Charles Carmakal, CTO of Mandiant Consulting, noted the trend of cyber adversaries targeting network devices, which often do not support Endpoint Detection and Response (EDR) solutions. This ongoing challenge emphasizes the need for enhanced security measures across network infrastructures.

The Hacker News Tags:Cisco, Cybersecurity, Exploit, Google, Mandiant, network security, root access, SD-WAN, Security, threat intelligence, Vulnerability, zero-day

Post navigation

Previous Post: Anthropic Alleges Alibaba’s Unauthorized Access to AI Models
Next Post: Cisco SD-WAN Exploit Exposed Months Before Patch

Related Posts

Redis Security Flaws Lead to Critical Patches Redis Security Flaws Lead to Critical Patches The Hacker News
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access The Hacker News
AI-Driven Phishing Toolkit Uncovered in WebDAV Campaign AI-Driven Phishing Toolkit Uncovered in WebDAV Campaign The Hacker News
Critical SGLang Vulnerability Allows Remote Code Execution Critical SGLang Vulnerability Allows Remote Code Execution The Hacker News
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider The Hacker News
FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ransomware Tactics: Disabling Security Before Encryption
  • Ghostjacking Threatens AI Security Through Trusted Tools
  • Passkey Flaws Exposed: New Attacks on Authentication Methods
  • Interlock Ransomware Exploits Windows Tools for Credential Theft
  • Cyberattacks Target Water Systems in New Jersey and Alabama

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ransomware Tactics: Disabling Security Before Encryption
  • Ghostjacking Threatens AI Security Through Trusted Tools
  • Passkey Flaws Exposed: New Attacks on Authentication Methods
  • Interlock Ransomware Exploits Windows Tools for Credential Theft
  • Cyberattacks Target Water Systems in New Jersey and Alabama

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark