logo

Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems

ID: 6c16ca93-5bc9-5352-aaf4-509428ca0d67

STIX ID: report--6c16ca93-5bc9-5352-aaf4-509428ca0d67

Feed Name: ThreatCluster

Threat Score
95/100

Date Published: 2026-05-14

Date Updated: 2026-05-15

...
...

Cisco disclosed a critical authentication-bypass zero-day (CVE-2026-20182) affecting Catalyst SD-WAN Controller and Manager, with a CVSS 10.0 rating and active exploitation by the actor UAT-8616; the flaw allows unauthenticated remote attackers to gain administrative privileges across cloud and on-prem deployments, Cisco released patches in May 2026 and organizations are urged to apply them immediately as no reliable workarounds exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.