Google’s Mandiant revealed a previously unknown vulnerability in Cisco’s Catalyst SD-WAN Manager. Attackers exploited the zero-day flaw, identified as CVE-2026-20245, to gain root-level access to a communications service provider.

Evidence shows the exploit was used as early as March 2026. Cisco did not disclose the vulnerability or issue a security patch until early June 2026.

Hackers created rogue user accounts with the highest system privileges to maintain control. The attackers employed anti-forensic techniques, including deleting files and restoring system configurations, to conceal their activity.