CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
ID: f2616a4a-5977-508f-8959-e184bb8c0f04
STIX ID: report--f2616a4a-5977-508f-8959-e184bb8c0f04
Feed Name: The Hacker News
CISA added a critical CVE-2026-20182 (CVSS 10.0) affecting Cisco Catalyst SD‑WAN Controller to its Known Exploited Vulnerabilities catalog after active exploitation attributed to UAT-8616; attackers bypass authentication to obtain administrative privileges and deploy web shells (XenShell, Godzilla, Behinder), multiple C2 frameworks, miners, and a credential stealer that attempts to exfiltrate admin hashes, JWT key chunks, and AWS credentials—CISA and Cisco recommend immediate remediation per their advisories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
