CyberSecurity News
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
AI summary
A high-severity security flaw in Cisco Catalyst SD-WAN was exploited by an unknown threat actor at least two months before its public disclosure. The vulnerability allows an authenticated local attacker to execute arbitrary commands with elevated privileges, giving them root access. This issue is tracked as CVE-2026-20245 and has a CVSS score of 7.8. Google-owned Mandiant made the discovery of the zero-day exploitation. The flaw was exploited before it was publicly known, highlighting its potential for misuse. The vulnerability's exploitation indicates a significant risk to affected systems.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

