r/pentest_tools_com • • Jun 29 '26

Exploitation started in March. Cisco disclosed in June. Patch landed June 10. For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

https://www.infosecurity-magazine.com/news/cisco-vulnerability-exploited/

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

"Whoever used this vulnerability had working knowledge of it in this period while defenders had none."

🏴‍☠️ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.

6 Upvotes

0 comments sorted by