# Cisco SD-WAN Zero-Day Exploited for Months to Establish Root Access and Network Persistence


## The Threat


A sophisticated threat actor exploited a critical vulnerability in Cisco Catalyst SD-WAN devices as a zero-day for at least two months before public disclosure, according to findings from Mandiant's incident response team. The flaw, CVE-2026-20245, allows an authenticated attacker with local network access to execute arbitrary commands with root-level privileges by uploading a crafted file to the device. The attacker leveraged this vulnerability to compromise a communications service provider's infrastructure, escalating from an administrative account to full system control and establishing persistent access to the SD-WAN fabric.


What makes this incident particularly concerning is the sophistication of the attack chain and the attacker's operational security discipline. Rather than a smash-and-grab exploitation, the threat actor methodically extracted configuration data, created hidden backdoor accounts, and systematically erased forensic evidence—including the malicious CSV file itself—to obscure the full scope of the compromise. The incident reveals how modern adversaries treat edge network devices not as afterthoughts, but as high-value targets worthy of extended, careful campaigns.


The exploitation likely began with one of two other undisclosed Cisco vulnerabilities (CVE-2026-20127 or CVE-2026-20182) that could bypass authentication on SD-WAN controllers, providing initial unauthorized peering connections. Mandiant documented two distinct waves of unauthorized activity: one spanning late 2025 through January 2026, and a second in March 2026. Whether these represent a single persistent attacker or independent threat actors exploiting the same victim remains unclear, but both campaigns demonstrate the same meticulous tradecraft in covering tracks and maintaining access without triggering alarms.


## Severity and Impact


| Field | Details |

|-------|---------|

| CVE | CVE-2026-20245 |

| CVSS Score | 7.8 (High) |

| CVSS Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |

| Attack Vector | Local |

| Attack Complexity | Low |

| Privileges Required | Low (netadmin role) |

| User Interaction | None |

| CWE | CWE-434 (Unrestricted Upload of File with Dangerous Type) |

| Scope | Unchanged |

| Confidentiality Impact | High |

| Integrity Impact | High |

| Availability Impact | High |


## Affected Products


  • Cisco Catalyst SD-WAN Manager — all versions prior to patching
  • Cisco Catalyst SD-WAN vSmart Controller — affected versions
  • Cisco Catalyst SD-WAN Edge devices — all affected platform models
  • Cisco SD-WAN vManage — administrative interface (vector for malicious file upload)

  • > Note: Cisco confirmed that authentication bypass flaws CVE-2026-20127 and CVE-2026-20182 were exploited in the same campaign. Organizations running Catalyst SD-WAN should assume multiple related vulnerabilities exist in their environment.


    ## Mitigations


    Immediate Actions:

  • Apply Cisco's security updates to Catalyst SD-WAN Manager, vSmart Controllers, and edge devices immediately. Prioritize systems connected to critical infrastructure or handling sensitive data flows.
  • Conduct credential rotation on all administrative accounts (admin, netadmin roles) on affected SD-WAN infrastructure. Do not assume current credentials are uncompromised.
  • Review /etc/passwd and /etc/shadow files on all SD-WAN controllers and edge devices for unexpected user accounts, particularly any entries created outside normal administration. Look for hidden accounts with root privileges.

  • Forensic and Detection:

  • Enable enhanced logging on SD-WAN management systems and controllers. Prioritize logging of file uploads, user account creation, and configuration changes.
  • Review system logs and configuration snapshots from late 2025 onward for unauthorized peering connections, CSV file uploads, or configuration rollbacks that may indicate cleaning activity.
  • Collect and preserve logs from SD-WAN analytics and telemetry systems, as attackers may attempt to delete local evidence but overlook centralized logging.
  • Search for evidence of the specific malicious filename evil_tenant.csv or related uploads in command history and syslog archives.

  • Preventative Controls:

  • Segment administrative access to SD-WAN controllers. Use network segmentation or privileged access management (PAM) solutions to restrict who can access management interfaces.
  • Implement certificate pinning and validation for SD-WAN peer connections. Stolen certificates (as documented in the March 2026 wave) should not be sufficient for peer authentication.
  • Deploy file upload restrictions and content validation on all SD-WAN management endpoints. Reject or quarantine CSV uploads that don't match expected schema.
  • Monitor for changes to default administrative credentials, particularly those that are later "restored" to original values—a hallmark of the cleanup activity observed in this incident.

  • ## References


  • Cisco Security Advisory: Catalyst SD-WAN Vulnerability Releases (official security notices from Cisco Security Center)
  • Mandiant Incident Response Report: Zero-Day Exploitation in SD-WAN Infrastructure (Google Mandiant threat intelligence publication)
  • CVSS v3.1 Calculator: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator (for scoring verification)
  • CWE-434: Unrestricted Upload of File with Dangerous Type — https://cwe.mitre.org/data/definitions/434.html

  • ---


    ## HackWire Analysis


    This incident illuminates a troubling shift in adversary targeting strategies: edge network devices like SD-WAN controllers are no longer peripheral security concerns—they are now primary targets for advanced threats seeking persistent, foundational access to enterprise infrastructure. Unlike traditional data center breaches, SD-WAN compromise grants attackers visibility into the fabric of internal traffic flows, making them invaluable for long-term espionage or lateral movement.


    The two-month pre-disclosure exploitation window is alarming but not surprising. Zero-day longevity has increased over the past 18 months, particularly for edge devices, because they generate less forensic telemetry than endpoints or servers. The attacker's diligent cleanup—deleting the malicious CSV, restoring configurations, creating hidden accounts, and even running validation scripts to confirm indicators were removed—shows a discipline that suggests either significant resources or prior rehearsal on a test environment.


    The March 2026 wave's reliance on stolen certificates is the real story here. It suggests either that the attacker maintained persistence from the January breach, or that certificate material leaked in a prior incident that defenders never detected or disclosed. This is a critical blind spot: enterprises routinely assume their SD-WAN certificates are secure because they assume the devices managing them are secure. That assumption is now broken.


    For defenders, the immediate imperative is threefold: patch all related CVEs (including the two authentication bypasses), implement aggressive certificate rotation and pinning, and assume that any SD-WAN device that was accessible to an attacker in the past six months may have been compromised. Organizations in highly regulated sectors (telecom, finance, energy) should treat this as a potential breach notification trigger and begin forensic investigations now rather than waiting for proof of exfiltration.


    The broader pattern here matters: Cisco, Fortinet, Juniper, and Palo Alto Networks have all seen zero-day exploitation of SD-WAN and edge security devices in 2025–2026. These are not random events. Threat actors have clearly prioritized network edge devices as a category because they deliver disproportionate access and operate in the blind spots of traditional security operations centers.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)