What We Know
REST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gapsREST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gaps
Older than 2 weeksJust now

Cisco SD-WAN Zero-Day Exploited Months Before Patching

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Older than 2 weeks

What We Know

Google Cloud’s Mandiant team has reported active exploitation of a vulnerability tracked as CVE-2026-20245 in Cisco Catalyst SD‑WAN Manager. According to the reporting, attackers used the flaw to gain root-level access; one account describes an intrusion that achieved the highest access level at a communications service provider. Multiple security outlets summarize Mandiant’s disclosure and warn the exploit was in use months prior to public disclosure and remediation.

Technical summaries in the coverage say the issue can be exploited via an authenticated file-upload vector that leads to full system compromise, and security firms and blogs (including Rescana, The Hacker News, CyberScoop and SecurityWeek) have published alerts urging operators to investigate and remediate. The activity was prominent enough for Google/Mandiant to publicize details to help defenders detect and block similar intrusions.

Source Comparison

Aligned reporting
8 corroborates - 0 adds context - 0 conflicts

Corroborates