IOC Radar
TLP:WHITE1 IOC

Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User

CA
Cyber Accord
Published June 5, 2026Original Report

Diamond Model

Attack Flow3 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/3
Exploit Public-Facing Application
ActionExploit public-facing application
Attackers exploit a vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise1

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2026-20245
exploitintel-blogmalware
High
59
Jun 5, 26

IOC Relationship Graph

IOC Relationship Graph1 total IOCs
CVE
CVE1REPORTCisco SD-WAN Vulnerability
scroll to zoom · drag to pan · click IOC to open