{"id":714,"date":"2026-06-29T16:56:35","date_gmt":"2026-06-29T11:26:35","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=714"},"modified":"2026-08-18T16:58:02","modified_gmt":"2026-08-18T11:28:02","slug":"cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/","title":{"rendered":"CVE-2026-20245: Cisco SD-WAN Zero-Day Attacks Gained Root Access"},"content":{"rendered":"<p>CVE-2026-20245 has moved from a Cisco advisory entry to a clearer incident story. Mandiant\u2019s latest analysis shows how attackers moved from unauthorized SD-WAN peering and administrative access to root-level control on Cisco Catalyst SD-WAN Manager using a crafted tenant-upload file and cleanup routines.<\/p>\n<p>Cisco had already warned that the high-severity flaw was exploited in a limited number of attacks, released fixed software, and stated that no workarounds address the vulnerability.<\/p>\n<p>Mandiant\u2019s report adds the operational detail: the vulnerability was not the first step. It was used after the attacker had access to SD-WAN Manager and could execute the vulnerable command-line workflow.<\/p>\n<p>That distinction matters. This was not only a patching issue. It was also a control-plane trust issue involving peering history, administrator accounts, device configuration data, and anti-forensic behavior that could reduce visibility after compromise.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tDetect and contain threats using Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>What the Disclosure Changes<\/h2>\n<p>The latest reporting gives defenders a more useful sequence than the advisory alone.<\/p>\n<p>Cisco disclosed a <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-command-injection\/\">command-injection<\/a> vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, Controller, and Validator.<\/p>\n<p>Mandiant&#8217;s investigation shows how the vulnerability was used as part of a broader intrusion targeting SD-WAN infrastructure at a service provider.<\/p>\n<p>Key details changed the response picture:<\/p>\n<ul>\n<li>The observed activity included rogue peering before the CVE-2026-20245 exploitation.<\/li>\n<li>Mandiant saw unauthorized peering connections and later SSH authentication to SD-WAN Manager using the vmanage-admin account.<\/li>\n<li>The attacker changed the default admin account password, accessed the web interface, and extracted SD-WAN configuration data.<\/li>\n<li>Mandiant noted that unauthorized peering from late 2025 to January 2026 may have involved <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-20127utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=cve_2026_20245\" target=\"_blank\" rel=\"noopener\">CVE-2026-20127<\/a> or CVE-2026-20182.<\/li>\n<li>Cisco told Mandiant the March connections did not use <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-20182utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=cve_2026_20245\" target=\"_blank\" rel=\"noopener\">CVE-2026-20182<\/a> and could have involved certificate material stolen during a previous compromise of the same device.<\/li>\n<\/ul>\n<p>That uncertainty should influence the incident response.<\/p>\n<p>Teams should avoid assuming that patching CVE-2026-20245 alone explains every unauthorized control-plane event.<\/p>\n<h2>How Root Access Was Reached<\/h2>\n<p>The exploit path centered on a tenant-upload function in the Cisco Catalyst SD-WAN command-line interface. After the attacker had administrative access, Mandiant observed the use of a crafted CSV file named evil_tenant.csv.<\/p>\n<p>The root-access sequence followed a clear pattern:<\/p>\n<ul>\n<li>The crafted CSV file triggered command injection during processing.<\/li>\n<li>The payload backed up sensitive files, including \/etc\/passwd and \/etc\/shadow.<\/li>\n<li>The attacker appended entries that created a root-privileged account named troot.<\/li>\n<li>Mandiant reported that the attacker used su to switch from the compromised administrative account to the rogue root account.<\/li>\n<li>The activity gave the attacker root-level access on the affected SD-WAN Manager device.<\/li>\n<\/ul>\n<p>This represents the primary risk associated with CVE-2026-20245.<\/p>\n<p>Once attackers obtain root access to a controller-class device, the impact extends beyond the appliance itself.<\/p>\n<p>SD-WAN control components may contain configuration data, templates, edge relationships, and certificate-based trust information.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-best-practices.jpg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity Best Practices for Businesses to Adopt in 2026<\/h4><p>Cybersecurity Best Practices for Businesses to Adopt in 2026<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-best-practices-2026-guide\/\" aria-label=\"Cybersecurity Best Practices for Businesses to Adopt in 2026\"><\/a><\/div><\/div><\/div>\n<h2>Why the Control Plane Became the Target<\/h2>\n<p>The incident highlights a broader SD-WAN security problem: centralized orchestration creates high operational value for defenders and high strategic value for attackers.<\/p>\n<p>A compromised SD-WAN control plane may expose:<\/p>\n<ul>\n<li>device inventory and controller relationships<\/li>\n<li>branch connectivity context<\/li>\n<li>edge-device and template configuration<\/li>\n<li>certificate or trust relationships between components<\/li>\n<li>information that could support follow-on activity<\/li>\n<\/ul>\n<p>Public reporting has not confirmed traffic interception or widespread network manipulation.<\/p>\n<p>However, confirmed attacker activity includes:<\/p>\n<ul>\n<li>Root-level access<\/li>\n<li>Extraction of SD-WAN configuration data<\/li>\n<li>Anti-forensic cleanup<\/li>\n<li>Configuration changes pushed to edge devices in a limited number of Cisco-observed cases<\/li>\n<\/ul>\n<p>The reported behavior also shows operational discipline. Mandiant said the attacker restored modified values, deleted malicious files, removed traces of the rogue account, and executed validation logic to confirm that visible indicators had been cleared.<\/p>\n<p>That makes timeline reconstruction harder and increases the importance of preserved diagnostics, peering records, and authentication logs.<\/p>\n<div class=\"qMYqUG_convSearchResultHighlightRoot\">\n<div class=\"\" data-turn-id-container=\"request-WEB:8030ca20-35a8-4e70-b27b-e4f55db24e8d-48\" data-is-intersecting=\"true\">\n<section class=\"text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]\" dir=\"auto\" data-turn-id=\"request-WEB:8030ca20-35a8-4e70-b27b-e4f55db24e8d-48\" data-turn-id-container=\"request-WEB:8030ca20-35a8-4e70-b27b-e4f55db24e8d-48\" data-testid=\"conversation-turn-80\" data-turn=\"assistant\">\n<div class=\"text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm\/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg\/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)\">\n<div class=\"[--thread-content-max-width:40rem] @w-lg\/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group\/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn\" data-conversation-screenshot-content=\"\">\n<div class=\"flex max-w-full flex-col gap-4 grow\">\n<div class=\"min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1\" dir=\"auto\" tabindex=\"0\" data-message-author-role=\"assistant\" data-message-id=\"c997ac04-84c9-44c1-b4d1-4a305669ba39\" data-message-model-slug=\"gpt-5-5-thinking\" data-turn-start-message=\"true\">\n<div class=\"flex w-full flex-col gap-1 empty:hidden\">\n<div class=\"markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling\">\n<h2 data-start=\"24\" data-end=\"77\">Exposure Signals Security Teams Should Prioritize<\/h2>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div>\n<\/div>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 21.4588%; text-align: left;\">Signal to Review<\/th>\n<th style=\"width: 39.7463%; text-align: left;\">Why It Matters<\/th>\n<th style=\"width: 37.6322%; text-align: left;\">What to Verify<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 21.4588%;\">Unauthorized peering events<\/td>\n<td style=\"width: 39.7463%;\">May indicate abnormal trust relationships in the SD-WAN fabric<\/td>\n<td style=\"width: 37.6322%;\">Source IPs, timing, device identity, and certificate use<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.4588%;\">vmanage-admin SSH activity<\/td>\n<td style=\"width: 39.7463%;\">Mandiant observed that this account was used during access<\/td>\n<td style=\"width: 37.6322%;\">External origins, unusual login times, and session history<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.4588%;\">Admin password changes<\/td>\n<td style=\"width: 39.7463%;\">Attackers reportedly changed and restored account credentials<\/td>\n<td style=\"width: 37.6322%;\">Rapid password changes, password-change history, and account audit records<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.4588%;\">Tenant-upload command execution<\/td>\n<td style=\"width: 39.7463%;\">CVE-2026-20245 was exploited through this workflow<\/td>\n<td style=\"width: 37.6322%;\">CLI history, script logs, and references to crafted CSV uploads<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.4588%;\">troot or root-level account traces<\/td>\n<td style=\"width: 39.7463%;\">Mandiant observed the creation of a rogue root account<\/td>\n<td style=\"width: 37.6322%;\">\/etc\/passwd, \/etc\/shadow, backups, and forensic remnants<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.4588%;\">Deleted temporary files<\/td>\n<td style=\"width: 39.7463%;\">Cleanup may remove obvious indicators<\/td>\n<td style=\"width: 37.6322%;\">Diagnostic bundles, recovered remnants, and preserved logs<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What Teams Should Verify Beyond the Patch<\/h2>\n<p>Security teams must patch affected systems and conduct a broader exposure review. Cisco released software updates and stated that no workarounds address the vulnerability.<\/p>\n<p>Security teams should prioritize four actions:<\/p>\n<ul>\n<li>Upgrade affected Cisco Catalyst SD-WAN Manager, Controller, and Validator components, then verify edge-device configurations where teams suspect exposure.<\/li>\n<li>Collect admin-tech diagnostics and retain relevant logs before upgrading.<\/li>\n<li>Hunt against the tactics, techniques, and indicators described by Mandiant.<\/li>\n<li>Escalate suspicious findings to Cisco TAC for admin-tech assessment and involve an incident-response team for deeper forensic investigation where needed.<\/li>\n<\/ul>\n<p>Credential and certificate reviews should be treated as a core part of the response, not an optional step.<\/p>\n<p>Mandiant&#8217;s reporting leaves open the possibility that stolen certificate material may have supported some peering activity.<\/p>\n<p>Teams should:<\/p>\n<ul>\n<li>Assess possible exposure of SD-WAN certificates<\/li>\n<li>Review administrator credentials<\/li>\n<li>Validate templates and device configuration data<\/li>\n<li>Rotate or reissue trust material where the investigation supports doing so<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp\" class=\"resource-box__image\" alt=\"the cybersecurity blueprint\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"the cybersecurity blueprint\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            The Cybersecurity Blueprint\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            A practical blueprint for choosing and implementing the right cybersecurity strategy for your business.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/the-cybersecurity-blueprint-how-to-adopt-the-right-cybersecurity-strategy-for-your-business\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Where Hexnode Fits After SD-WAN Exposure<\/h2>\n<p>This is not a direct detection story for Hexnode. The primary activity occurred on Cisco SD-WAN infrastructure and requires Cisco logs, SD-WAN diagnostics, <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-siem\/\">SIEM<\/a> data, and network telemetry for investigation.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help teams:<\/p>\n<ul>\n<li>Use Hexnode UEM device reports and inventory data to identify managed administrator endpoints for post-incident review.<\/li>\n<li>Review compliance status across privileged workstations<\/li>\n<li>Enforce security policies on devices used for network administration<\/li>\n<li>Maintain endpoint inventory and update posture<\/li>\n<li>Execute supported remote actions on managed noncompliant administrator endpoints<\/li>\n<\/ul>\n<p>Hexnode XDR can help teams:<\/p>\n<ul>\n<li>Review endpoint posture and agent status on managed Windows endpoints<\/li>\n<li>Investigate endpoint incidents and security events on managed administrator workstations<\/li>\n<li>Check endpoint action history during post-exposure review<\/li>\n<li>Query endpoint telemetry in Hexnode XDR to analyze suspicious activity on managed Windows devices.<\/li>\n<li>Verify security policy deployment status across relevant endpoint groups<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>CVE-2026-20245 shows why security teams must treat SD-WAN controllers as critical control-plane assets, not ordinary infrastructure appliances. Root-level access, rogue peering, and anti-forensic cleanup can leave teams questioning network trust even after they update the vulnerable software.<\/p>\n<p>Security teams should preserve diagnostics, retain relevant logs, upgrade affected systems, validate peering history, review administrator access, rotate exposed trust material where needed, and improve visibility across endpoints used to manage SD-WAN environments.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen endpoint control after exposure <\/h5><p>Start your 14-day free trial and improve endpoint visibility. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is CVE-2026-20245 remotely exploitable without authentication?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Cisco describes CVE-2026-20245 as requiring authenticated local access. Mandiant reported that the attacker used it after gaining access to affected SD-WAN devices.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What data could the Cisco SD-WAN attack have exposed?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Mandiant reported the extraction of configuration information for edge devices, controllers, and templates. Organizations should assess possible exposure of configuration data, administrator credentials, or certificate material in their environment.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Are indicators of compromise available?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Mandiant published indicators and hunting guidance, including network indicators, file artifacts, and log patterns. Teams should validate indicators against their own SD-WAN topology to reduce false positives.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>CVE-2026-20245 has moved from a Cisco advisory entry to a clearer incident story. Mandiant\u2019s latest&#8230;<\/p>\n","protected":false},"author":5,"featured_media":721,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,20],"class_list":["post-714","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-network-and-vpn","product_category-identity-provider","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2026-20245: Cisco SD-WAN Root Access<\/title>\n<meta name=\"description\" content=\"CVE-2026-20245 exploitation gave attackers root access on Cisco Catalyst SD-WAN devices after rogue peering and admin abuse.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-20245: Cisco SD-WAN Root Access\" \/>\n<meta property=\"og:description\" content=\"CVE-2026-20245 exploitation gave attackers root access on Cisco Catalyst SD-WAN devices after rogue peering and admin abuse.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-29T11:26:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:28:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cve-2026-20245.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"CVE-2026-20245: Cisco SD-WAN Zero-Day Attacks Gained Root Access\",\"datePublished\":\"2026-06-29T11:26:35+00:00\",\"dateModified\":\"2026-08-18T11:28:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/\"},\"wordCount\":1293,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cve-2026-20245.jpeg?format=webp\",\"articleSection\":[\"Zero-Day\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/\",\"name\":\"CVE-2026-20245: Cisco SD-WAN Root Access\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cve-2026-20245.jpeg?format=webp\",\"datePublished\":\"2026-06-29T11:26:35+00:00\",\"dateModified\":\"2026-08-18T11:28:02+00:00\",\"description\":\"CVE-2026-20245 exploitation gave attackers root access on Cisco Catalyst SD-WAN devices after rogue peering and admin abuse.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cve-2026-20245.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cve-2026-20245.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"cve-2026-20245\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-20245: Cisco SD-WAN Zero-Day Attacks Gained Root Access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2026-20245: Cisco SD-WAN Root Access","description":"CVE-2026-20245 exploitation gave attackers root access on Cisco Catalyst SD-WAN devices after rogue peering and admin abuse.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-20245: Cisco SD-WAN Root Access","og_description":"CVE-2026-20245 exploitation gave attackers root access on Cisco Catalyst SD-WAN devices after rogue peering and admin abuse.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-29T11:26:35+00:00","article_modified_time":"2026-08-18T11:28:02+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cve-2026-20245.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"CVE-2026-20245: Cisco SD-WAN Zero-Day Attacks Gained Root Access","datePublished":"2026-06-29T11:26:35+00:00","dateModified":"2026-08-18T11:28:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/"},"wordCount":1293,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cve-2026-20245.jpeg?format=webp","articleSection":["Zero-Day","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/","name":"CVE-2026-20245: Cisco SD-WAN Root Access","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cve-2026-20245.jpeg?format=webp","datePublished":"2026-06-29T11:26:35+00:00","dateModified":"2026-08-18T11:28:02+00:00","description":"CVE-2026-20245 exploitation gave attackers root access on Cisco Catalyst SD-WAN devices after rogue peering and admin abuse.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cve-2026-20245.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cve-2026-20245.jpeg?format=webp","width":1340,"height":700,"caption":"cve-2026-20245"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20245-cisco-sd-wan-zero-day-attacks-gained-root-access\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-20245: Cisco SD-WAN Zero-Day Attacks Gained Root Access"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=714"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/714\/revisions"}],"predecessor-version":[{"id":725,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/714\/revisions\/725"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/721"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}