Researchers have released new details on the exploitation of CVE-2026-20245, a high-severity vulnerability affecting Cisco Catalyst SD-WAN Manager that was actively exploited as a zero-day at least two months before its public disclosure. The attackers combined the flaw with previously exploited authentication bypass vulnerabilities to gain administrative access before escalating privileges to root by uploading a malicious CSV file. The campaign demonstrates a sophisticated, multi-stage intrusion targeting enterprise network infrastructure. Following successful exploitation, the threat actor created a hidden root-level account (“troot”), modified administrator credentials, exfiltrated SD-WAN fabric configuration data, and then restored the original passwords while deleting forensic evidence to evade detection. According to Mandiant, the attacker also executed validation scripts to confirm that indicators of compromise had been removed, highlighting an advanced level of operational security designed to maintain long-term persistence within the victim environment. The incident underscores the continued targeting of network infrastructure devices that typically lack endpoint detection and response (EDR) capabilities. Organizations operating Cisco Catalyst SD-WAN deployments should immediately apply Cisco’s security updates, review systems for unauthorized user accounts and configuration changes, audit authentication and peering logs, and restrict management interfaces to trusted networks. As attackers increasingly focus on edge devices to establish persistent access, rapid patching and continuous monitoring of network infrastructure remain critical components of enterprise cyber defence.