logo

Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access

ID: 436db175-8acc-5e99-a268-ed25722636e0

STIX ID: report--436db175-8acc-5e99-a268-ed25722636e0

Feed Name: cybersecurityNews.com

Threat Score
95/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Guru Baran

...
...

**Executive Summary:** A critical zero-day (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD‑WAN Controller allows unauthenticated attackers to bypass authentication by claiming device type vHub over DTLS (UDP/12346), inject SSH keys into /home/vmanage-admin/.ssh/authorized_keys, and obtain persistent NETCONF (TCP/830) administrative access across SD‑WAN deployments; Rapid7 confirmed active exploitation and published a Metasploit module. Cisco has no workaround—customers must apply listed fixed releases and gather forensic evidence (request admin-tech) before upgrade; defenders should audit auth.log for unexpected "Accepted publickey for vmanage-admin" entries and check control connection states for anomalous challenge-ack values.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.