Home · Briefs · CTI Daily Brief — 2026-06-27
UPDATE: Mandiant documents the full Cisco Catalyst SD-WAN exploitation chain — CSV-injection to a root backdoor
From CTI Daily Brief — 2026-06-27 · published 2026-06-27
UPDATE (originally covered 2026-06-26): Google Mandiant (GTIG) published (2026-06-24) the first complete TTP chain for the Cisco Catalyst SD-WAN Manager zero-day activity, observed at a service-provider victim from late 2025 into 2026 (Google Mandiant, 2026-06-24). NCSC-CH amended its Security Hub post to add the report on 2026-06-25 (NCSC-CH Security Hub post 12579).
The chain: authentication bypass via
CVE-2026-20182/CVE-2026-20127(rogue peering connection), then privilege escalation viaCVE-2026-20245— a maliciousevil_tenant.csvuploaded through therequest tenant-uploadCLI carries unsanitised shell commands that append atrootroot user to/etc/passwdand/etc/shadow, after which the actor reverts configuration changes and deletes the file for anti-forensics. This gives defenders concrete hunts the earlier advisory could not: search SD-WAN Manager instances for unexpected/etc/passwdadditions,evil_tenant.csvartefacts, andrequest tenant-uploadexecution in CLI logs.