logo

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

ID: f2616a4a-5977-508f-8959-e184bb8c0f04

STIX ID: report--f2616a4a-5977-508f-8959-e184bb8c0f04

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: [email protected] (The Hacker News)

...
...

CISA added a critical CVE-2026-20182 (CVSS 10.0) affecting Cisco Catalyst SD‑WAN Controller to its Known Exploited Vulnerabilities catalog after active exploitation attributed to UAT-8616; attackers bypass authentication to obtain administrative privileges and deploy web shells (XenShell, Godzilla, Behinder), multiple C2 frameworks, miners, and a credential stealer that attempts to exfiltrate admin hashes, JWT key chunks, and AWS credentials—CISA and Cisco recommend immediate remediation per their advisories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.