logo

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

ID: ad69a2ac-6754-59ab-af0c-91af23fe9a50

STIX ID: report--ad69a2ac-6754-59ab-af0c-91af23fe9a50

Feed Name: Bleeping Computer

Threat Score
92/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Lawrence Abrams

...
...

Cisco warns of CVE-2026-20182, a critical (CVSS 10.0) authentication-bypass in Catalyst SD‑WAN Controller and Manager that has been actively exploited to gain administrative (non-root) access, enabling NETCONF access and the registration of rogue peers; Cisco released patches, recommends restricting management interfaces and reviewing /var/log/auth.log and SD‑WAN peering logs for IOCs, and CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.