# Cisco SD-WAN Critical Flaw Under Active Exploit for Two Months Before Public Disclosure
Mandiant researchers have uncovered evidence that attackers were actively exploiting a critical privilege escalation vulnerability in Cisco Catalyst SD-WAN Controller since March 2026, roughly two months before the company disclosed the flaw on June 4, 2026. The discovery raises urgent questions about the timeline between active exploitation in the wild and vendor disclosure—a gap that left countless SD-WAN deployments exposed and unpatched.
## The Vulnerability
CVE-2026-20245 affects the command line interface (CLI) of Cisco Catalyst SD-WAN Controller and stems from insufficient input validation. The flaw allows attackers who already possess administrator (netadmin) credentials to escalate their privileges to root-level access, effectively gaining complete control of the device.
The vulnerability is classified as critical, with a CVSS score reflecting its severity. However, Cisco initially downplayed the risk by asserting that exploitation required either:
Cisco released patches on June 12, 2026, eight days after the initial disclosure, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20245 to its Known Exploited Vulnerabilities (KEV) catalog on June 4.
## Attack Timeline: Active Exploitation Before Disclosure
The most alarming aspect of this incident is the timeline. Google's Mandiant threat intelligence team discovered evidence of active exploitation dating back to March 2026—a full two months before Cisco's June 4 disclosure. This gap represents a critical window during which attackers held a significant advantage over defenders, with working exploits in circulation while organizations remained unaware of the vulnerability.
| Date | Event |
|------|-------|
| March 2026 | Attackers begin exploiting CVE-2026-20245 in the wild |
| Late 2025 – January 2026 | Mandiant discovers attack campaign during SD-WAN infrastructure investigation |
| June 4, 2026 | Cisco discloses CVE-2026-20245; CISA adds to KEV catalog |
| June 12, 2026 | Final patches released by Cisco |
| June 23, 2026 | CISA deadline for Federal Civilian Executive Branch (FCEB) remediation |
Mandiant identified the vulnerability while investigating attacks against SD-WAN infrastructure at a service provider. The investigation spanned from late 2025 through January 2026, meaning researchers were tracking the exploitation campaign for months before it became public knowledge.
## Technical Details: How the Attack Works
Understanding the attack chain is essential for organizations assessing their exposure. The attack unfolds in multiple stages:
### Initial Access via Rogue Peering
The attack begins with what Mandiant describes as "rogue peering connections" to the victim's SD-WAN Manager devices. SD-WAN peering is a legitimate process in which different components—such as edge routers and central control points—authenticate each other using cryptographic certificates. This enables safe data exchange across the SD-WAN fabric.
Attackers exploit this trust mechanism by:
1. Compromising existing access to the SD-WAN environment, likely through exploitation of CVE-2026-20127 or CVE-2026-20182 (the two previously disclosed zero-days)
2. Establishing rogue peering connections by spoofing or hijacking legitimate certificate-based authentication
3. Gaining SD-WAN Manager access with elevated but non-root privileges
### Privilege Escalation via CVE-2026-20245
Once inside with administrator credentials, attackers exploit the input validation flaw in the CLI to execute commands that escalate to root-level access. The specific technical mechanism involves:
With root access, attackers gain complete control of the SD-WAN Controller, enabling them to:
## Who Was Targeted?
Mandiant's investigation identified attacks targeting service providers managing SD-WAN infrastructure. This is particularly concerning because service providers operate SD-WAN controllers on behalf of multiple customers, meaning a single compromised device could provide attackers with visibility into dozens or hundreds of enterprise networks.
The targeting suggests a sophisticated threat actor with knowledge of:
## Cisco's Response and Patching Timeline
Cisco acknowledged the vulnerability on June 4 and released patches on June 12. The company emphasized that:
However, the two-month gap between active exploitation and disclosure means that any organization compromised during that period may not yet know they were targeted. Attackers could have maintained persistent access, exfiltrated data, or positioned themselves for lateral movement while the vulnerability remained undisclosed.
## Federal Response and Remediation Deadline
CISA's inclusion of CVE-2026-20245 in the KEV catalog triggered mandatory remediation requirements for federal agencies. The June 23, 2026 deadline for the Federal Civilian Executive Branch requires agencies to either:
This aggressive timeline reflects the severity of active exploitation and federal vulnerability to supply-chain attacks through service provider SD-WAN infrastructure.
## Implications for Organizations
### SD-WAN as Critical Infrastructure
SD-WAN deployments have become critical infrastructure for enterprises, consolidating branch connectivity, security policies, and network management. A compromised SD-WAN Controller provides attackers with a chokepoint for monitoring and manipulating all traffic that flows through the fabric.
Key risk areas:
### The Zero-Day Chaining Problem
This incident demonstrates a growing threat pattern: attackers combining multiple zero-days into a complete exploitation chain. Organizations that had patched one of the earlier zero-days but remained vulnerable to the other faced compound risk. A single unpatched system in the chain could provide full network compromise.
---
## HackWire Analysis
This incident exposes a critical blind spot in the vulnerability disclosure timeline: the assumption that attackers and defenders learn about vulnerabilities simultaneously. The two-month gap between active exploitation and disclosure is not unusual—it's becoming the norm for sophisticated supply-chain attacks.
What makes CVE-2026-20245 particularly instructive is how it was discovered. Mandiant found it *retrospectively*, while investigating a breach that had already occurred, rather than through defensive monitoring or vulnerability research. This suggests that the real exploitation likely extended beyond March; the March date simply marks when Mandiant has *evidence* of active attacks. The actual exploitation window could be significantly longer.
More concerning is the targeting pattern: service providers managing SD-WAN for multiple customers. A single compromised SD-WAN Controller provides attackers with visibility into dozens of enterprise networks simultaneously. The attacker gains what security researchers call "strategic advantage"—they can observe competitor activity, intercept customer communications, and choose which organizations to target for deeper compromise. This transforms the vulnerability from a single-organization risk into a supply-chain amplifier.
For defenders, the practical lesson is uncomfortable: assume that any SD-WAN infrastructure that was vulnerable during the March-June window was compromised. The threat actor's sophistication (knowledge of two separate zero-days, understanding of peering mechanisms, targeting of service providers) indicates they were likely successful in multiple environments. Organizations should:
1. Assume breach and verify: Conduct threat hunting for indicators of compromise during the window when CVE-2026-20127, CVE-2026-20182, and CVE-2026-20245 were all unpatched
2. Audit peering relationships: Review logs of SD-WAN peering authentications for anomalies, rogue certificates, or unexpected connection attempts
3. Monitor for persistence: Attackers maintaining root access would likely install backdoors or steal credentials; look for unusual system changes or credential compromise
4. Expand the scope: Contact SD-WAN service providers to confirm patching status and ask for forensic evidence of whether your organization's traffic was affected
The vendor disclosure timeline also matters for product evaluation. Organizations evaluating or renewing SD-WAN contracts should factor in Cisco's disclosure practices and patch velocity when comparing solutions. A critical flaw exploited for two months before disclosure suggests either limited security research transparency, insufficient vulnerability monitoring, or both.
— HackWire Editorial
---
## Recommendations for Security Teams
Immediate actions (within 7 days):
Short-term (within 30 days):
Long-term:
---
## Related Coverage