:

CISCO SD-WAN ZERO-DAY LET HACKERS CREATE ROOT ACCOUNTS

AI DESK2 MIN READ
WED, JUN 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Mandiant has detailed how attackers exploited a Cisco Catalyst SD-WAN vulnerability (CVE-2026-20245) in zero-day attacks to gain root access and establish rogue administrator accounts on compromised devices.

Security researchers at Mandiant have released technical analysis of how the Cisco SD-WAN vulnerability was weaponized in active attacks. The flaw allowed threat actors to bypass authentication mechanisms and achieve root-level privileges on Catalyst SD-WAN edge devices. The zero-day attacks resulted in the creation of unauthorized root accounts, granting attackers persistent administrative access to affected infrastructure. This level of access enables complete device control, including the ability to intercept traffic, modify configurations, and establish persistent footholds within enterprise networks. SD-WAN (Software-Defined Wide Area Network) devices are critical infrastructure components used by organizations to manage branch office connectivity. Compromise of these devices poses significant risk to network security and data integrity. Cisco has released patches to address CVE-2026-20245. The company urged customers to apply updates immediately, particularly organizations running vulnerable versions of Catalyst SD-WAN software. Mandiant's disclosure includes technical details on the exploitation chain, helping organizations understand the attack methodology and validate their remediation efforts. The firm noted that the vulnerability required no user interaction and could be exploited remotely by unauthenticated attackers. Organizations should prioritize patching SD-WAN devices, review access logs for suspicious account creation, and audit administrative accounts for unauthorized activity. Security teams should also consider isolating affected devices from production networks until patches are verified and deployed. This vulnerability adds to a growing list of critical infrastructure flaws discovered in networking equipment. Mandiant recommends organizations implement network segmentation and monitor SD-WAN devices for anomalous behavior as interim defensive measures.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

More than 50 ads containing AI-generated child sexual abuse material appeared on Facebook, Instagram, Messenger, and Threads, with some running as recently as this week, according to Meta's ad library data.

JUST NOWAI Desk

AI-generated phishing infrastructure is evolving faster than blocklists can track, rendering domain-based security strategies obsolete. Browser-level detection focused on attack techniques offers a more effective defense.

2H AGOAI Desk

Google Blogger has locked and deleted hundreds of blogs following a false positive that incorrectly flagged them for malware violations. The error affected sites across the platform without warning.

2H AGOSecurity Desk

A vulnerability in WebKit allows IP addresses and DNS queries to bypass proxy browsers and Apple's iCloud Private Relay, undermining privacy protections for users relying on these services.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.