Cisco warns that a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller is being exploited in the wild as a zero-day. The flaw, tracked as CVE-2026-20182 and rated CVSS 10.0, affects the peering authentication mechanism used by Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN Manager). Because the issue occurs in authentication, successful exploitation can allow attackers to gain administrative privileges on affected devices or gain admin access through the SD-WAN management/control components. Multiple outlets report Cisco has released patches to address the problem and that exploitation is not limited to a single campaign, with reporting indicating “limited” activity in some cases and “zero-day” exploitation by a sophisticated threat actor. Coverage also notes this is the second time this year Cisco has faced a maximum-severity (CVSS 10.0) vulnerability leveraged by threat actors in its network control system. The affected functionality involves the peering relationship used for SD-WAN operations, and the issue is reported to impact both on-premises and cloud deployments. Cisco’s guidance focuses on applying the released updates to mitigate the risk of administrative compromise.
Cisco Issues Fix for Actively Exploited Catalyst SD-WAN Authentication Bypass Zero-Day
Cisco warns that a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller is being exploited in the wild as a zero-day. The flaw, tracked as CVE-2026-20182 and rated CVSS 10.0,...
- Cisco discloses CVE-2026-20182, a CVSS 10.0 authentication bypass flaw in Catalyst SD-WAN Controller/Manager.
- The vulnerability affects the peering authentication mechanism used between SD-WAN components.
- Multiple reports say CVE-2026-20182 is actively exploited in the wild as a zero-day.
- Successful exploitation can allow attackers to obtain administrative privileges or admin access.
- Cisco releases patches and coverage notes the flaw impacts both on-prem and cloud deployments.
Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of the Cisco Catalyst SD-WAN solution) and Cisco Catalyst SD-WAN Manager (the management plane for the entire SD-WAN fabric) – stems from a flawed peering authentication mechanism. It affects both on-prem and cloud deployments. CVE-2026-20182 was reported … More → The post Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182) appeared first on Help Net Security.
3 months agoThis is the second time this year a threat actor has leveraged a CVSS 10.0 vulnerability in Cisco's network control system.
3 months agoCisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices. [...]
3 months agoCisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0. "A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly
3 months ago
Yankees’ George Lombard Jr. leaves Red Sox game with right knee discomfort
New York Yankees rookie shortstop George Lombard Jr. exits the second game of a doubleheader against the Boston Red Sox...
Moses Itauma gasses out as corner stops IBF world title fight versus Filip Hrgovic
Moses Itauma is stopped in the ninth round of his IBF world title fight against Filip Hrgovic after he “gasses out,” wit...
Norway’s King Haakon VIII pays tribute to late King Harald V in first address
Norway’s new king, Haakon VIII, delivers his first speech as sovereign and pays an emotional tribute to his late father,...