VULNERABILITY OVERVIEW
A command injection flaw (CWE-116) in the Cisco Catalyst SD-WAN Manager CLI allows an authenticated attacker with netadmin privileges to upload a crafted file (evil_tenant.csv) to execute arbitrary commands as root, creating unauthorized root accounts (named 'troot' in observed intrusions). Mandiant identified this as the seventh actively exploited Cisco SD-WAN zero-day of 2026, attributing the campaign to a highly operationally mature threat actor (likely UAT-8616) that exploited CVE-2026-20245 as a zero-day at least two months before disclosure, then used extensive anti-forensic cleanup to erase evidence. The flaw is chained after authentication bypasses CVE-2026-20182 (CVSS 10.0) or CVE-2026-20127 for initial access; CISA added CVE-2026-20245 to KEV on June 4, 2026. Cisco confirmed that exploitation resulted in unauthorized configuration pushes to downstream edge devices across entire SD-WAN deployments.
CVSS BREAKDOWN
Cisco Catalyst SD-WAN Manager versions 20.18.2.1 and earlier; all deployment types (on-prem, Cloud-Pro, Cisco Managed Cloud, FedRAMP) — fixed in 20.18.3.1CITATIONS
- → https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager
- → https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html
- → https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
- → https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- → https://nvd.nist.gov/vuln/detail/CVE-2026-20245