Signal

Cisco patches critical authentication bypass zero-day in Catalyst SD-WAN amid active exploitation

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-14 16:00 UTCUpdated 2026-05-15 14:11 UTC
rss
cveexploitssecurity_advisoriesincident_responsesecurity_policy
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Overview

Cisco has released a patch for a critical authentication bypass vulnerability (CVE-2026-20182) affecting its Catalyst SD-WAN Controller and Manager platforms. The flaw, rated CVSS 10.0, allows unauthenticated remote attackers to gain administrative privileges by bypassing peering authentication.

Entities
CiscoRapid7Palo Alto NetworksCisco Catalyst SD-WAN ControllerCisco Catalyst SD-WAN ManagerPAN-OSDouglas McKeeHarsh Jaiswal
Score total
1.99
Momentum 24h
11
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
9%
Why now
  • The flaw is currently being exploited in the wild, increasing immediate risk to organizations.
  • Cisco has just released patches, but no workarounds exist, making prompt updates critical.
  • This is the sixth exploited zero-day in Cisco SD-WAN products in 2026, indicating a persistent attack trend.
Why it matters
  • The vulnerability allows unauthenticated attackers to gain full admin access, risking network control and data integrity.
  • Active exploitation by a known threat actor highlights ongoing targeted attacks on critical infrastructure.
  • CISA's directive to patch federal systems underscores the vulnerability's severity and urgency.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • CVE-2026-20182 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager allowing unauthenticated remote attackers to gain administrative privileges.
  • The vulnerability has been actively exploited in limited targeted attacks by a sophisticated threat actor known as UAT-8616.
  • CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch by May 17, 2026.
How sources frame it
  • Cisco Systems: neutral
All evidence
All evidence
Cisco zero-day under ongoing attack by persistent threat group
Cyberscoop · cyberscoop.com · 2026-05-15 14:11 UTC
Cisco warns of an actively exploited SD-WAN flaw with max severity
Csoonline · csoonline.com · 2026-05-15 11:43 UTC
Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026
SecurityWeek · securityweek.com · 2026-05-15 06:28 UTC
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Thehackernews · thehackernews.com · 2026-05-15 05:28 UTC
Cisco Catalyst SD-WAN Manager: CVSS (Max): 8.6
Auscert · portal.auscert.org.au · 2026-05-14 23:43 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 11
Top publishers (this list)
  • Cyberscoop (1)
  • Therecord (1)
  • Csoonline (1)
  • SecurityWeek (1)
  • Thehackernews (1)
  • Auscert (1)
Top origin domains (this list)
  • cyberscoop.com (1)
  • therecord.media (1)
  • csoonline.com (1)
  • securityweek.com (1)
  • thehackernews.com (1)
  • portal.auscert.org.au (1)