logo

Cisco Catalyst SD-WAN Controller 0-Day Exploited for Admin Access

ID: 60926f64-896a-5452-ba32-9ad639392c0f

STIX ID: report--60926f64-896a-5452-ba32-9ad639392c0f

Feed Name: Cyber Press

Threat Score
95/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: AnuPriya

...
...

**Executive summary:** A critical zero-day vulnerability (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD-WAN controllers (vSmart/vManage) enables unauthenticated attackers to impersonate a vHub via a DTLS vdaemon authentication bypass, inject an SSH public key into the vmanage-admin account, gain NETCONF privileged access, and take full control of the SD-WAN control plane; limited active exploitation has been observed and Cisco has released patches and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.