📰 IT NachrichtenKI-Assistent: Anthropic vereint Claude Chat, Cowork und Artifacts(16.09.2026 um 19:03 Uhr)
💾 IT Security ToolsGitHub Release: trufflesecurity/trufflehog v3.97.5 (16.09.2026)(16.09.2026 um 19:51 Uhr)
📰 IT NachrichtenKI-Assistent: Anthropic vereint Claude Chat, Cowork und Artifacts(16.09.2026 um 19:03 Uhr)
💾 IT Security ToolsGitHub Release: trufflesecurity/trufflehog v3.97.5 (16.09.2026)(16.09.2026 um 19:51 Uhr)

📰 IT Security Nachrichten 🕛 vor 2 Monaten 3 Min Lesezeit CVE-2026-20127
0

CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access

Cyber Threat & Vulnerability Dossier CVSS 9.8 CRITICAL (Heuristik) EPSS 84.8%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-269: Privilege Management
Handlungsempfehlung: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
Im CVE-Radar öffnen
↗ Quelle (thecyberexpress.com)
🔬 IoC Intelligence (10 Indikatoren erkannt)
CVE-2026-20245CVE-2026-20127CVE-2026-2018220[.]9[.]9[.]220[.]12[.]7[.]220[.]15[.]4[.]520[.]15[.]5[.]320[.]18[.]3[.]1+2 weitere
🗣️ Stimme:
📑 Inhaltsübersicht

CVE-2026-20245

A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root access and used extensive anti-forensic measures to erase evidence of the attack. 

Threat Actor Abused Cisco Catalyst SD-WAN Manager to Gain Root Access 


Mandiant found that the threat actor initially established unauthorized peering connections before accessing Cisco Catalyst SD-WAN Manager over SSH. In March 2026, the attacker authenticated using the default vmanage-admin account, changed the default admin account password, logged into the web interface, and exfiltrated SD-WAN fabric configurations, including device, controller, and template information.  

The original password was then restored to reduce the likelihood of detection. The researchers noted that neither the vmanage-admin nor admin accounts provide root shell access, prompting the attacker to because Cisco Catalyst SD-WAN Manager fails to properly filter malicious data uploaded through its tenant file upload feature. The  0 
Reported to Cisco by Mandiant, CVE-2026-20245 affects the command-line interface of Cisco Catalyst SD-WAN Controllers and allows an authenticated local attacker to execute arbitrary commands as root through a specially crafted file. 

The malicious affecting peering authentication that allow remote attackers to bypass authentication and gain administrative privileges. 

Further rogue peering activity in March 2026 targeted software versions not vulnerable to CVE-2026-20127. Cisco confirmed the activity also did not rely on CVE-2026-20182, suggesting the  seeking long-term intelligence collection. 

Organizations are advised to collect diagnostic logs using the request admin-tech command, investigate any indicators of compromise, and report confirmed incidents to Cisco TAC. Cisco recommends upgrading Cisco Catalyst SD-WAN Manager to versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later to remediate CVE-2026-20245 and following its SD-WAN hardening guidance. 

Recovered indicators include the malicious evil_tenant.csv file with SHA-256 hash b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b and rogue IP addresses including 126.51.108[.]152, 76.92.245[.]217, 207.190.37[.]94, 23.245.7[.]178, 153.186.231[.]233, 167.179.79[.]189, 45.32.38[.]160, and 209.137.225[.]101.  

Google SecOps also released detections covering behaviors associated with the threat actor, while Mandiant acknowledged Cisco PSIRT for its collaboration during the coordinated disclosure process. 
Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf thecyberexpress.com.
↗ Original-Artikel auf thecyberexpress.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
GitHub Release: nodejs/node v26.9.0 (16.09.2026)
1 Quelle
First VMmark 4.1 Power-Performance and VMware Cloud Foundation 9.1 Results
1 Quelle
O&O Defrag Download - Festplatten defragmentieren
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access

Thematisch verwandte Begriffe: CVE202620245, ZeroDay, Exploited, Cisco · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...