Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
ID: 671b6fea-175f-5c3c-934c-81625b5dac2a
STIX ID: report--671b6fea-175f-5c3c-934c-81625b5dac2a
Feed Name: The Hacker News
Threat Score
Cisco released patches for CVE-2026-20182, a maximum-severity (CVSS 10.0) authentication bypass in Catalyst SD-WAN Controller (vdaemon over DTLS/UDP 12346) that can let unauthenticated attackers become authenticated peers with administrative privileges and alter NETCONF/network configuration; Rapid7 discovered the flaw and Cisco reported limited exploitation in May 2026, urging immediate updates and log audits for suspicious peering events and unauthorized publickey logins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
