NASA’s new dark energy space telescope can also detect killer asteroids
technologyreview.com·1h ago

TL;DR
A zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager allowed attackers to escalate privileges from an admin account to root access. The vulnerability was due to inadequate filtering of malicious data during file uploads.
✦ Why It Matters
Engineers should enhance file upload security and implement monitoring to detect unauthorized access attempts.
Key Takeaways
How It Works
The vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated user to upload a malicious CSV file that executes arbitrary commands as root. By exploiting this flaw, the attacker created a new user account with full privileges while backing up original system files to avoid detection.
Related