Mandiant details Cisco SD-WAN CVE-2026-20245 exploitation with root escalation, rogue peering, credential changes, and cleanup scripts. Act now.
What this zero-day does to SD-WAN control
CVE-2026-20245 is a Cisco SD-WAN zero-day that Mandiant has documented in active exploitation. The reported path is not a single noisy crash-and-run event. It chains into root-level control of affected SD-WAN components, then into changes that reshape how the fabric trusts peers and operators. Once an attacker has root, they can alter configuration, plant persistence, and operate with the same authority as legitimate management software.
Two outcomes stand out in the public detail: rogue peering and credential changes. Rogue peering means an attacker can introduce or accept unauthorized control-plane relationships so traffic and management paths no longer match the design you think you have. Credential changes mean operator and service accounts may no longer be trustworthy even if the UI still looks normal. Treat any confirmed exposure as a full control-plane compromise until proven otherwise.
Immediate actions if you run Cisco SD-WAN
Act now. Isolate management interfaces from general enterprise networks and the public internet where they are not strictly required. Freeze nonessential configuration changes so you have a clean before-and-after baseline. Capture running configs, peer lists, certificate and key material references, and authentication source settings before you remediate, then store those artifacts offline.
- Inventory every SD-WAN controller, edge, and management path that could accept the vulnerable surface, including lab and DR copies.
- Compare current peers, tunnels, and trust anchors against a known-good design; flag any peer, route policy, or control connection you cannot explain.
- Rotate credentials and secrets that the platform can influence: local admins, API tokens, shared keys, and any integrated directory or SSO bindings used for SD-WAN admin access.
- Apply vendor fixes or mitigations as soon as they are available for your exact role and deployment model; do not wait for a full forensic report to start containment.
Root escalation, rogue peering, and credential abuse
Root escalation is the force multiplier. With root, an attacker can disable or rewrite logging, install persistence, and modify how the node authenticates peers. Rogue peering then extends the blast radius: a compromised node can become a trusted foothold for intercepting, injecting, or steering control and data paths. Credential changes close the loop by locking out defenders or creating backdoor accounts that survive a naive “reboot and hope” response.
When you hunt, do not only look for malware filenames. Look for unexpected peer relationships, sudden admin password or key updates, new local users, altered AAA settings, and configuration diffs that do not match change tickets. Correlate SD-WAN management logs with identity-provider logs and out-of-band network telemetry so a compromised controller cannot be the only source of truth.
Cleanup scripts and how to use them safely
Mandiant’s write-up covers cleanup scripts as part of the response picture. Scripts are useful for consistent removal of known indicators and for restoring a baseline, but they are not a substitute for scoping. Run them only after you understand what they change, on systems you have already isolated and imaged if evidence matters, and only from a trusted copy of the guidance—not from an unreviewed attachment or mirror.
After cleanup, rebuild trust deliberately: re-establish peering from verified configs, reissue or rebind credentials, re-enable monitoring, and watch for reintroduction of the same peer or account patterns. Keep an incident timeline of containment, eradication, and recovery steps. A zero-day against the SD-WAN control plane is a network-wide trust event; treat restoration as re-proving the fabric, not merely clearing a single host alert.