Security researchers at Google-owned Mandiant have identified that a high-severity vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20245, was exploited as a zero-day by unknown threat actors. The exploitation occurred at least two months before the flaw was publicly disclosed and patched. The vulnerability carries a CVSS score of 7.8, reflecting its potential impact on enterprise network infrastructure.
The flaw allows an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system. By successfully exploitation the vulnerability, attackers were able to gain root access to the affected devices. This level of access grants a threat actor full control over the SD-WAN component, potentially allowing for deeper persistence within the network environment.
Mandiant's findings highlight a period of unauthorized access that predates the official security advisory. While the investigation into the specific threat actor remains ongoing, the activity emphasizes the risks associated with authenticated local access flaws being leveraged to bypass standard security controls on critical networking hardware.
For CIOs and operations leaders, this incident underscores the importance of monitoring for unauthorized privilege escalation even within authenticated sessions. IT departments should ensure that all Cisco Catalyst SD-WAN environments are updated to the latest firmware versions to mitigate the risks associated with this exploited zero-day vulnerability.
The BroadVision view
Zero-day exploitation of SD-WAN infrastructure allows unauthorized parties to gain administrative control before software updates are released. For mid-market organizations, this underscores the necessity of continuous network monitoring and rapid patching protocols to protect edge devices. Security teams must prioritize visibility across wide area networks to detect anomalies that bypass traditional perimeter defenses. Learn more about BroadVision managed IT services.
