Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
What happened
Mandiant released technical details showing attackers exploited a Cisco Catalyst SD‑WAN command‑injection zero‑day to create rogue root accounts in vendor management consoles. The report links the privilege escalation to prior unauthorized peering and tenant-upload features, highlighting that the attack chain often involved chaining older bypasses to reach root. Watch for additional IoCs and supplier confirmations about certificate or prior-compromise reuse
Why the category manager should care
Treat SD‑WAN controllers and vendor consoles as high‑value assets; require supplier proof they’ve audited all management-plane access because these consoles can grant global control
Key facts
- Exploit chain escalated to root via crafted tenant upload
- Rogue SD‑WAN peering activity observed beginning in March
- Mandiant links CVE-2026-20245 exploitation to prior authentication bypass activity