logo

CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday

ID: b7d3dc2b-0d0c-55b5-a78f-58637d5a1849

STIX ID: report--b7d3dc2b-0d0c-55b5-a78f-58637d5a1849

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

CVE-2026-20182 is a critical (10/10) authentication-bypass vulnerability in Cisco SD-WAN that can allow unauthenticated remote attackers to obtain administrative privileges; Cisco has released a patch and CISA has issued emergency guidance requiring agencies to inventory affected systems, collect logs, hunt for compromise, and report findings. Rapid7 discovered the flaw while researching a related bug, exploitation has been observed in the wild, and analysts warn the vulnerability is attractive to nation-state actors seeking persistent access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.