IC Technology & Surveillance — 2026-06-25
Mandiant Reveals State-Sponsored Zero-Day Exploitation of Cisco SD-WAN Gave Root Access at Communications Provider
BLUFRoot access to a communications provider's SD-WAN management plane exposed network-wide traffic to collection, and the actor's validated anti-forensic cleanup makes named-group attribution within 90 days unlikely at low confidence.
Mandiant reported on June 24 that a threat actor exploited CVE-2026-20245, a privilege-escalation zero-day in Cisco Catalyst SD-WAN Manager patched by Cisco on June 4, to gain root access at an unnamed communications service provider 12. Mandiant identified two distinct periods of unauthorized activity: an initial intrusion spanning late 2025 through January 2026, and a second campaign beginning in March 2026 in which the actor authenticated via the vmanage-admin account, extracted SD-WAN fabric configurations, then uploaded a crafted CSV file that injected a rogue root account named "troot" into the device's system files 13. The actor deleted exploit artifacts, restored modified configurations, and ran a validation script confirming trace removal; Mandiant stated the cleanup prevented full assessment of the compromise's scope 12. Mandiant did not name a specific threat group but stated in its report that the TTPs are "consistent with previously documented cyber espionage threat actor behavior" 12.
AnalysisRoot access to an SD-WAN management plane yields visibility into routed traffic across the provider's entire network, not a bounded session. The actor's sequencing of fabric configuration exfiltration before privilege escalation indicates topology mapping ahead of deeper collection. Based on Mandiant's technical report alone, public attribution to a named nation-state group within 90 days of disclosure is
unlikely. The actor's cleanup script validated artifact removal before the compromise's scope could be bounded, and low confidence reflects that anti-forensic activity destroyed the forensic record that named-group attribution requires. A second actor may have conducted initial access via stolen certificate material separately from whoever exploited CVE-2026-20245, further complicating attribution. Until a named-actor profile emerges, communications providers face hardening decisions against an undefined espionage actor with no targeting pattern to orient threat hunts.
3 sources
- Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager - Mandiant (Google Cloud)
- Malicious hackers exploit Cisco zero-day for highest access level at communications service provider - CyberScoop
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access - BleepingComputer
View in full brief →