Mandiant: Cisco SD-WAN Manager zero-day exploited for months
Mandiant reports that a threat actor exploited the zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager from late 2025 to January 2026, after gaining access to a service provider's SD-WAN environment. The actor used rogue peering and credential manipulation, then escalated to root through a malicious CSV upload. From there it created a root-level account, extracted SD-WAN configuration data, and applied extensive cleanup and anti-forensic steps to conceal the intrusion. The vulnerability was patched on 4 June.
What this means for your organisation
The attack ran through the service provider and onward into the customer environment. That is the form of supplier risk NIS2 is clearest about: your security is no better than the management systems of whoever runs your network. Extracting SD-WAN configuration hands the attacker a map of the whole network, and the anti-forensic work means an absence of traces is not an acquittal.
Berigo recommends
- Ask your network provider to confirm in writing that the 4 June update is installed, and for their own assessment of exposure.
- Review accounts with root or administrator rights in the SD-WAN environment and remove any that cannot be explained.
- Require the provider to forward relevant logs into your own environment, so logging cannot be erased locally.
- Put an incident notification duty for supplier-side events into the contract, with defined deadlines.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch