logo

CVE-2026-20182: Critical Authentication Bypass in Cisco SD-WAN Can Grant Admin Access

ID: e6ed7285-1159-5b1b-add8-82d842bf177a

STIX ID: report--e6ed7285-1159-5b1b-add8-82d842bf177a

Feed Name: SOC Prime Blog

Threat Score
95/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: SOC Prime Team

...
...

CVE-2026-20182 is a critical (CVSS 10.0) authentication-bypass in Cisco Catalyst SD-WAN Controller/Manager allowing an unauthenticated attacker to be treated as a trusted control-plane peer via a crafted DTLS/handshake sequence; successful exploitation can append SSH keys, manipulate NETCONF/configuration, and grant broad administrative control. Rapid7 published technical analysis and a Metasploit module, Cisco reported limited exploitation in May 2026 and linked activity to UAT-8616, and CISA added the flaw to its Known Exploited Vulnerabilities catalog; Cisco recommends immediate upgrade to fixed releases and collecting admin-tech bundles for forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.