logo

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

ID: 671b6fea-175f-5c3c-934c-81625b5dac2a

STIX ID: report--671b6fea-175f-5c3c-934c-81625b5dac2a

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: [email protected] (The Hacker News)

...
...

Cisco released patches for CVE-2026-20182, a maximum-severity (CVSS 10.0) authentication bypass in Catalyst SD-WAN Controller (vdaemon over DTLS/UDP 12346) that can let unauthenticated attackers become authenticated peers with administrative privileges and alter NETCONF/network configuration; Rapid7 discovered the flaw and Cisco reported limited exploitation in May 2026, urging immediate updates and log audits for suspicious peering events and unauthorized publickey logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.