Skip to main content

Share story

Security

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Image: Primary
Mandiant reported June 24, 2026 that a threat actor exploited a zero-day vulnerability tracked as CVE-2026-20245 in Cisco Catalyst SD-WAN Manager. In early 2026 the actor targeted SD-WAN infrastructure at a service provider. After gaining initial access, the actor used the flaw to escalate privileges from a compromised administrative account to root-level access. The vulnerability exists in the command-line interface of Cisco Catalyst SD-WAN Controllers and allows an authenticated local attacker to execute arbitrary commands as root by supplying a crafted file. The actor exploited the issue via a malicious CSV upload named evil_tenant.csv using the command request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0. Mandiant said the vulnerability stems from the device file upload feature lacking the ability to properly filter malicious data. The actor created a root account named troot and performed extensive anti-forensic cleanup including deleting files and restoring modified configurations. Cisco released patches in versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2 and later. The vulnerability was reported to Cisco by Mandiant.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Google Cloud Blog and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

Security
Security

NFM Lending faces lawsuit after acknowledged cyber incident

NFM Lending faces a class-action lawsuit after acknowledging a cybersecurity incident, The Tech Edvocate reports. Former customer Sheneka Smith alleges that the mortgage lender failed to maintain reasonable safeguards for customer...

AI Capital
AI Capital

Chinese local governments offer incentives to AI filmmakers

Reuters reports that Chinese local governments are offering computing vouchers, rent waivers and dedicated funding to attract filmmakers using artificial intelligence. These incentives reduce the cost of computing and premises for...

Security AI
Security AI

GitHub Security Lab releases agent workflow for automated fuzz testing

GitHub Security Lab has published a workflow that uses an AI agent to set up and run fuzz tests for C and C++ projects. Given a repository, it selects functions to test, writes test harnesses, runs AFL++, checks which code the tes...