:

CISCO SD-WAN ZERO-DAY LET HACKERS CREATE ROOT ACCOUNTS

AI DESK2 MIN READ
WED, JUN 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Mandiant has detailed how attackers exploited a Cisco Catalyst SD-WAN vulnerability (CVE-2026-20245) in zero-day attacks to gain root access and establish rogue administrator accounts on compromised devices.

Security researchers at Mandiant have released technical analysis of how the Cisco SD-WAN vulnerability was weaponized in active attacks. The flaw allowed threat actors to bypass authentication mechanisms and achieve root-level privileges on Catalyst SD-WAN edge devices. The zero-day attacks resulted in the creation of unauthorized root accounts, granting attackers persistent administrative access to affected infrastructure. This level of access enables complete device control, including the ability to intercept traffic, modify configurations, and establish persistent footholds within enterprise networks. SD-WAN (Software-Defined Wide Area Network) devices are critical infrastructure components used by organizations to manage branch office connectivity. Compromise of these devices poses significant risk to network security and data integrity. Cisco has released patches to address CVE-2026-20245. The company urged customers to apply updates immediately, particularly organizations running vulnerable versions of Catalyst SD-WAN software. Mandiant's disclosure includes technical details on the exploitation chain, helping organizations understand the attack methodology and validate their remediation efforts. The firm noted that the vulnerability required no user interaction and could be exploited remotely by unauthenticated attackers. Organizations should prioritize patching SD-WAN devices, review access logs for suspicious account creation, and audit administrative accounts for unauthorized activity. Security teams should also consider isolating affected devices from production networks until patches are verified and deployed. This vulnerability adds to a growing list of critical infrastructure flaws discovered in networking equipment. Mandiant recommends organizations implement network segmentation and monitor SD-WAN devices for anomalous behavior as interim defensive measures.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

As encrypted communications become harder to intercept, law enforcement agencies are increasingly turning to hacking suspects' devices directly rather than breaking encryption. This shift marks a new phase in the ongoing tension between privacy and security.

7H AGOSecurity Desk

A critical macOS vulnerability allowing remote attackers to gain complete system control without passwords is actively being exploited in the wild. The bug affects the built-in screen-sharing functionality across multiple Mac systems.

10H AGOSecurity Desk

Multiple water treatment facilities across the United States have been compromised in recent weeks by attackers allegedly connected to the Iranian government. The breach marks a significant intrusion into critical infrastructure systems.

10H AGOSecurity Desk

A PBS station is at risk of losing 50 terabytes of archived content after its cloud storage provider, Iron Mountain, became unresponsive and denied access to the data. The station has no backup copies of the material.

10H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.