DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:01:53ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
UAC-0145 (Sandworm) CRITICAL — UAC-0145 is a confirmed sub-cluster of Sandworm, Russia's GRU-affiliated advanced hacking… /// CYLINDRICALCANINE CRITICAL — CylindricalCanine is a newly named operational subgroup within the China-linked… /// @CrowdStrike CRITICAL — July 2026 Patch Tuesday analysis: CVE-2026-56155 (AD FS EoP, CVSS 7.8) confirmed… /// @MsftSecIntel CRITICAL — Microsoft has confirmed active exploitation of CVE-2026-56155 in Active Directory… /// @GossiTheDog CRITICAL — CVE-2026-56155 ADFS zero-day is nastier than the CVSS 7.8 suggests. Admin on your ADFS…
26Critical Threats
18Active CVEs
10IOCs Tracked
5New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20245PUBLISHED: 2026-06-04
HIGHCVE-2026-20245★ CISA KEV LISTED

Cisco Catalyst SD-WAN Manager CLI Command Injection Zero-Day (Root Escalation)

VENDOR: Cisco//PRODUCT: Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), Validator (vBond)
7.8
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

A command injection flaw (CWE-116) in the Cisco Catalyst SD-WAN Manager CLI allows an authenticated attacker with netadmin privileges to upload a crafted file (evil_tenant.csv) to execute arbitrary commands as root, creating unauthorized root accounts (named 'troot' in observed intrusions). Mandiant identified this as the seventh actively exploited Cisco SD-WAN zero-day of 2026, attributing the campaign to a highly operationally mature threat actor (likely UAT-8616) that exploited CVE-2026-20245 as a zero-day at least two months before disclosure, then used extensive anti-forensic cleanup to erase evidence. The flaw is chained after authentication bypasses CVE-2026-20182 (CVSS 10.0) or CVE-2026-20127 for initial access; CISA added CVE-2026-20245 to KEV on June 4, 2026. Cisco confirmed that exploitation resulted in unauthorized configuration pushes to downstream edge devices across entire SD-WAN deployments.

Attack Vector
LOCAL
Attack Complexity
LOW
Privs Required
HIGH
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSCisco Catalyst SD-WAN Manager versions 20.18.2.1 and earlier; all deployment types (on-prem, Cloud-Pro, Cisco Managed Cloud, FedRAMP) — fixed in 20.18.3.1
  • https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager
  • https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-20245
SHARE BRIEF:✕ Post on Xin Share on LinkedIn