Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access
ID: 436db175-8acc-5e99-a268-ed25722636e0
STIX ID: report--436db175-8acc-5e99-a268-ed25722636e0
Feed Name: cybersecurityNews.com
**Executive Summary:** A critical zero-day (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD‑WAN Controller allows unauthenticated attackers to bypass authentication by claiming device type vHub over DTLS (UDP/12346), inject SSH keys into /home/vmanage-admin/.ssh/authorized_keys, and obtain persistent NETCONF (TCP/830) administrative access across SD‑WAN deployments; Rapid7 confirmed active exploitation and published a Metasploit module. Cisco has no workaround—customers must apply listed fixed releases and gather forensic evidence (request admin-tech) before upgrade; defenders should audit auth.log for unexpected "Accepted publickey for vmanage-admin" entries and check control connection states for anomalous challenge-ack values.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
