A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. Exploiting a bug in the platform's file upload functionality, the threat actor escalated its privileges from a compromised administrator account to root access and used extensive detection measures to erase traces of the attack.
See also: Cisco fixes zero-day vulnerability in Catalyst SD-WAN

Mandiant found that the threat actor initially established unauthorized peering connections before gaining access to the Cisco Catalyst SD-WAN Manager via SSH. In March 2026, the attacker authenticated using the default vmanage-admin account, changed the default admin account password, logged into the web interface, and exported SD-WAN fabric configurations, including device, controller, and template information.
The original password was then restored to reduce the likelihood of detection. The researchers noted that neither the vmanage-admin nor admin accounts provide root shell access, forcing the attacker to exploit CVE-2026-20245 for privilege escalation.
CVE-2026-20245 Exploited via Malicious CSV Upload The vulnerability exists because Cisco Catalyst SD-WAN Manager fails to properly filter malicious data uploaded via the tenant file upload feature. The threat actor exploited CVE-2026-20245 by uploading a crafted file named evil_tenant.csv using the command:
request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0
Reported to Cisco by Mandiant, CVE-2026-20245 affects the command-line interface of Cisco Catalyst SD-WAN controllers and allows an authenticated local attacker to execute arbitrary commands as root via a specially crafted file.
The malicious payload backed up configuration files, kept copies of /etc/passwd and /etc/shadow, and created a new root-level account named troot. Mandiant later observed the threat actor switching from the admin account to troot using the su command.
Mandiant observed multiple unauthorized peering connections between late 2025 and January 2026. Researchers believe these may have exploited CVE-2026-20127 or CVE-2026-20182, two critical Cisco vulnerabilities that affect peering authentication and allow remote attackers to bypass authentication and gain administrative privileges.
See also: RoguePlanet Zero-Day: New Microsoft Defender vulnerability gives SYSTEM access

Further malicious peering activity in March 2026 targeted software versions that were not vulnerable to CVE-2026-20127. Cisco confirmed that the activity was also not based on CVE-2026-20182, suggesting that the threat actor may have reused stolen certificate material from a previous breach. Mandiant said it remains unclear whether the same group conducted both campaigns.
To hide the intrusion, the threat actor deleted evil_tenant.csv, restored the modified configuration files, removed temporary objects, and ran a validation script to confirm that the malicious files, troot account, and modified configuration files had been removed or restored.
Consequences and Mitigation
Mandiant said the campaign reflects the growing trend of “living off the edge,” where attackers target network devices that often lack granular detection visibility while providing centralized control in operational environments. Such platforms remain attractive to state-sponsored actors seeking long-term intelligence collection.
Organizations are advised to collect diagnostic logs using the request admin-tech command, investigate any indicators of compromise, and report confirmed incidents to Cisco TAC. Cisco recommends upgrading Cisco Catalyst SD-WAN Manager to versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2 , or later to mitigate CVE-2026-20245 and follow the SD-WAN hardening guidance.
The recovered indicators include the malicious file evil_tenant.csv with the SHA-256 hash b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b and malicious IP addresses such as 126.51.108[.]152, 76.92.245[.]217, 207.190.37[.]94, 23.245.7[.]178, 153.186.231[.]233, 167.179.79[.]189, 45.32.38[.]160, and 209.137.225[.]101.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Microsoft condemns public Zero-Day disclosures

Google SecOps also released detections covering behaviors related to the threat actor, while Mandiant recognized Cisco PSIRT for its collaboration during the coordinated disclosure process.
