Attackers spent five months inside service-provider SD-WAN, then added a root account called troot and cleaned up after themselves
2026-08-16Security
Mandiant documented CVE-2026-20245 in Cisco Catalyst SD-WAN Manager — a CSV upload that runs as root. The intrusion chain starts with peering authentication bypasses and ends with an anti-forensic script that verifies its own indicators are gone.