A sophisticated intrusion campaign targeting SD-WAN infrastructure at a service provider, culminating in the exploitation of a previously unknown vulnerability to achieve root-level system access.
The zero-day, now tracked as CVE-2026-20245, resides in the CLI of Cisco Catalyst SD-WAN Controllers and stems from the device’s file upload feature failing to properly filter malicious input data.
Between late 2025 and January 2026, Mandiant observed multiple unauthorized peering connections targeting the victim’s SD-WAN Manager devices.
Catalyst SD-WAN Manager Zero-Day Exploited
Researchers believe these intrusions may have leveraged two critical authentication bypass vulnerabilities, CVE-2026-20127 and CVE-2026-20182, both of which allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on Cisco Catalyst SD-WAN controllers.
Neither vulnerability had been publicly disclosed or patched during this period. By March 2026, the threat actor expanded activity on a device running software unaffected by CVE-2026-20127.
Cisco confirmed the March connections also did not leverage CVE-2026-20182, suggesting the attacker may have used stolen certificate material from a prior compromise of the same device.
After establishing unauthorized SSH access via the vmanage-admin account, the threat actor changed the password on the default admin account and authenticated directly to the SD-WAN Manager web interface.
Using this session, the attacker exfiltrated SD-WAN fabric configurations, including device templates, edge router details, and controller topology via sequential API calls to the /dataservice/ endpoints.
To reduce detection risk, the threat actor subsequently restored the admin account password to its original value before terminating the session, mimicking normal operational behavior.
With an active admin SSH session established, the attacker exploited CVE-2026-20245 by uploading a malicious file named evil_tenant.csv.
The exploit payload within the CSV appended malicious entries to the system’s /etc/passwd and /etc/shadow files, creating a new user account named troot with full UID 0 root privileges.
The script also backed up original configuration files including vbond_vsmart_tenant_list to allow clean restoration after exploitation, preventing invalid configurations from alerting administrators.
The threat actor then accessed the troot account from the admin session using the su command.
Mandiant observed the threat actor executing a structured validation script after completing their objectives. The script systematically verified the removal of all created files in /home/admin/, confirmed deletion of the troot entries from /etc/passwd and /etc/shadow, and checked whether the original vbond_vsmart_tenant_list had been restored.
This methodical approach reflects a disciplined operational security posture designed to minimize forensic artifacts on the compromised device.
Mitigation
Organizations running Cisco Catalyst SD-WAN Manager should take the following immediate steps:
- Patch immediately: Upgrade to fixed releases versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later
- Run
request admin-techon all control-plane components to collect diagnostic logs for IOC sweeping - Engage Cisco TAC if any confirmed indicators of compromise are identified
- Implement hardening controls per the Cisco Catalyst SD-WAN Hardening Guide
This campaign exemplifies the growing trend of state-linked threat actors targeting edge network appliance environments that often lack deep telemetry, operate as central control planes, and present a stealthy platform for long-term strategic access.
Google Threat Intelligence Group has tracked a steady rise in zero-day exploitation of edge devices over the past four years, and this intrusion reinforces that SD-WAN orchestrators are now firmly in the crosshairs.
Indicators of Compromise (IOCs)
| Description | Indicator |
| IP address connecting as rogue device and exploiting CVE-2026-20245 | 126.51.108[.]152 |
| IP address connecting as rogue device | 76.92.245[.]217 |
| IP address connecting as rogue device | 207.190.37[.]94 |
| IP address connecting as rogue device | 23.245.7[.]178 |
| IP address connecting as rogue device | 153.186.231[.]233 |
| IP address connecting as rogue device | 167.179.79[.]189 |
| IP address connecting as rogue device | 45.32.38[.]160 |
| IP address connecting as rogue device | 209.137.225[.]101 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.