Affected Systems

Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.

Exploitation Status

Active exploitation confirmed. Mandiant has published technical details on attacker exploitation methods. Threat actors are using this zero-day to gain root access in the wild.

Business Impact

Critical impact for organizations using Cisco Catalyst SD-WAN. Attackers achieve full root access, enabling complete device compromise, persistent backdoor creation via rogue accounts, potential network segmentation bypass, and lateral movement. SD-WAN devices are high-value targets controlling WAN traffic routing and site connectivity. Compromise can lead to traffic interception, manipulation, or denial of service across the WAN infrastructure.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately audit all Cisco Catalyst SD-WAN devices for unauthorized root accounts and suspicious user additions in system logs
  • Apply Cisco security patches for CVE-2026-20245 as soon as available; contact Cisco TAC for emergency mitigation guidance if patches unavailable
  • Review SD-WAN device authentication logs and configuration changes for indicators of compromise, focusing on privilege escalation and account creation events
  • Implement network segmentation to isolate SD-WAN management interfaces from untrusted networks and restrict administrative access to known IP ranges
  • Enable enhanced logging and forward SD-WAN device logs to SIEM for continuous monitoring of authentication anomalies and configuration changes

---

# Threat Actor Context

Actor Profile

This report describes a campaign exploiting CVE-2026-20245, a zero-day vulnerability in Cisco Catalyst SD-WAN infrastructure. No specific threat actor has been attributed to this exploitation activity. Mandiant disclosed technical details of the vulnerability exploitation, which allowed attackers to gain root-level access on targeted devices. The motivation appears to be establishing persistent administrative access to network infrastructure through the creation of rogue root accounts, enabling long-term control of SD-WAN devices in networking and telecommunications environments.

TTPs (Tactics, Techniques, Procedures)

The campaign leveraged CVE-2026-20245, a zero-day vulnerability in Cisco Catalyst SD-WAN devices, to achieve initial access and privilege escalation. Key TTPs include: T1190 (Exploit Public-Facing Application) - exploitation of the SD-WAN zero-day vulnerability; T1078.003 (Valid Accounts: Local Accounts) - creation of rogue root accounts for persistence; T1068 (Exploitation for Privilege Escalation) - leveraging the vulnerability to gain root access; T1136.001 (Create Account: Local Account) - establishing unauthorized root-level accounts on compromised devices. The exploitation enabled attackers to maintain persistent administrative control over network infrastructure devices.

Targets & Patterns

The campaign targeted organizations in the networking and telecommunications sectors, specifically those utilizing Cisco Catalyst SD-WAN infrastructure. These sectors are attractive targets due to their critical role in network operations and the potential for lateral movement across enterprise networks. SD-WAN devices represent high-value targets as they manage wide-area network connectivity and often have visibility into multiple network segments. Compromise of these devices provides attackers with strategic positioning for network reconnaissance, traffic interception, and potential pivot points for further intrusion activities. The focus on infrastructure devices suggests sophisticated adversaries seeking persistent access to critical network components.

Historical Context

Zero-day exploitation of network infrastructure devices, particularly SD-WAN and edge networking equipment, has been a recurring pattern in advanced persistent threat campaigns. Cisco devices have been targeted in previous campaigns by various APT groups seeking to establish footholds in enterprise networks. The creation of rogue administrative accounts as a persistence mechanism is consistent with infrastructure-focused intrusion tradecraft observed in campaigns targeting routers, switches, and network management platforms. Mandiant's disclosure follows industry patterns of security vendors revealing exploitation details after patches become available or active exploitation is detected in the wild.

Defensive Recommendations

  • Immediately patch CVE-2026-20245 on all Cisco Catalyst SD-WAN devices and conduct forensic review of device configurations and user accounts
  • Audit all local accounts on SD-WAN infrastructure, particularly root and administrative accounts, for unauthorized additions or modifications (T1136.001)
  • Implement network segmentation to isolate SD-WAN management interfaces from untrusted networks and enforce strict access controls (T1190)
  • Enable comprehensive logging on network infrastructure devices and monitor for privilege escalation events, account creation, and configuration changes (T1068, T1078.003)
  • Deploy detection rules for anomalous authentication patterns to SD-WAN devices, including logins from unusual source IPs or at irregular times