Cisco Catalyst SD-WAN Controller 0-Day Exploited for Admin Access
ID: 60926f64-896a-5452-ba32-9ad639392c0f
STIX ID: report--60926f64-896a-5452-ba32-9ad639392c0f
Feed Name: Cyber Press
Threat Score
**Executive summary:** A critical zero-day vulnerability (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD-WAN controllers (vSmart/vManage) enables unauthenticated attackers to impersonate a vHub via a DTLS vdaemon authentication bypass, inject an SSH public key into the vmanage-admin account, gain NETCONF privileged access, and take full control of the SD-WAN control plane; limited active exploitation has been observed and Cisco has released patches and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
