What We Know
Google Cloud’s Mandiant team has reported active exploitation of a vulnerability tracked as CVE-2026-20245 in Cisco Catalyst SD‑WAN Manager. According to the reporting, attackers used the flaw to gain root-level access; one account describes an intrusion that achieved the highest access level at a communications service provider. Multiple security outlets summarize Mandiant’s disclosure and warn the exploit was in use months prior to public disclosure and remediation.
Technical summaries in the coverage say the issue can be exploited via an authenticated file-upload vector that leads to full system compromise, and security firms and blogs (including Rescana, The Hacker News, CyberScoop and SecurityWeek) have published alerts urging operators to investigate and remediate. The activity was prominent enough for Google/Mandiant to publicize details to help defenders detect and block similar intrusions.
Source Comparison
Aligned reportingCorroborates
- cloud.google.com↗Confirms Mandiant/Google Cloud disclosure of active exploitation of CVE-2026-20245 in Cisco Catalyst SD‑WAN Manager and provides public guidance intended to help defenders detect and block similar intrusions.
- cyberscoop.com↗Describes an intrusion that achieved the highest access level at a communications service provider and reports attackers exploited a previously unknown Cisco vulnerability, aligning with Mandiant's account.
- securityweek.com↗Reports that the Cisco SD‑WAN zero‑day (CVE‑2026‑20245) was exploited months before it was patched and cites Google's Mandiant disclosure, matching the briefing's timeline.
- infosecurity-magazine.com↗Summarizes Google's warning that the Cisco Catalyst SD‑WAN vulnerability was exploited months before public disclosure, corroborating Mandiant's findings on active exploitation.
- thehackernews.com↗Details exploitation of CVE‑2026‑20245 in Cisco Catalyst SD‑WAN that enabled root access, matching the briefing's technical impact and attribution to active attacks.
- rescana.com↗Issues an active exploitation alert stating CVE‑2026‑20245 enables root access via an authenticated file‑upload vector, corroborating the briefing's technical description and remediation urgency.
- itbrief.news↗Notes Mandiant's disclosure of a zero‑day root breach in Cisco SD‑WAN Manager, corroborating the briefing's claims about impact and public reporting.
- itbrief.com.au↗Reiterates Mandiant's findings about a zero‑day root breach in Cisco Catalyst SD‑WAN Manager, supporting the briefing's central timeline and impact claims.