CVE-2026-20182
published 2026-05-14CVE-2026-20182: May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February…
PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-05-17
Exploited in the wild
EPSS
88.50%
99.8th percentile
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Affected
179 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_sd-wan_manager | < 20.9.9.1 | 20.9.9.1 |
| cisco | catalyst_sd-wan_manager | — | — |
| cisco | catalyst_sd-wan_manager | >= 20.10 < 20.12.5.4 | 20.12.5.4 |
| cisco | catalyst_sd-wan_manager | >= 20.12.6 < 20.12.6.2 | 20.12.6.2 |
| cisco | catalyst_sd-wan_manager | >= 20.13 < 20.15.4.4 | 20.15.4.4 |
| cisco | catalyst_sd-wan_manager | >= 20.15.5 < 20.15.5.2 | 20.15.5.2 |
| cisco | catalyst_sd-wan_manager | >= 20.16 < 20.18.2.2 | 20.18.2.2 |
| cisco | catalyst_sd-wan_manager | >= 26.1 < 26.1.1.1 | 26.1.1.1 |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
| cisco | cisco_catalyst_sd-wan_controller | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Audit /var/log/auth.log for 'Accepted publickey for vmanage-admin' entries from unknown or unauthorized IP addresses as an indicator of exploitation. ↗
- →Hunt for suspicious peering events in logs: unauthorized peer connections at unexpected times, from unrecognized IPs, or involving device types inconsistent with the environment's architecture. ↗
- →The exploit targets the 'vdaemon' service over DTLS on UDP port 12346; monitor for unexpected or anomalous DTLS traffic to this port on SD-WAN controllers. ↗
- →Post-compromise, UAT-8616 attempted to add SSH keys, modify NETCONF configurations, and escalate to root privileges — monitor for unauthorized SSH key additions and NETCONF config changes. ↗
- →Detect creation of hidden local accounts (e.g., 'troot') in /etc/passwd and /etc/shadow on SD-WAN controller systems as a post-exploitation indicator. ↗
- →Monitor for malicious CSV file uploads to the SD-WAN Manager interface (e.g., filenames like evil_tenant.csv) as a vector for privilege escalation via CVE-2026-20245. ↗
- →Threat actor infrastructure overlaps with Operational Relay Box (ORB) networks; correlate inbound connections to SD-WAN controllers against known ORB network indicators. ↗
- →Detect web shell deployment (Godzilla, Behinder, XenShell variants) on SD-WAN systems; these allow operators to run arbitrary bash commands post-exploitation. ↗
- →Use the SD-WAN advisory's 'Show Control Connections' guidance to audit active peering connections for unauthorized peers. ↗
- ·CVE-2026-20182 is a distinct vulnerability from CVE-2026-20127 — it is not a patch bypass. Both affect the same 'vdaemon' service/DTLS stack but are different issues. ↗
- ·Systems accessible over the internet with exposed ports are at increased risk; internet-facing SD-WAN controllers should be treated as highest priority for patching. ↗
- ·In the March 2026 second wave, Cisco confirmed the rogue peering connections did NOT leverage CVE-2026-20182; stolen certificates from a prior breach may have been used instead. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
cisa·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] CWE-287 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Vulnerability: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Affected: Cisco Catalyst SD-WAN
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Notes: CISA Mitigation Instructio
GHSA
GHSA-p83j-mxpw-gqpj: May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in
ghsa_unreviewed·2026-05-14
CVE-2026-20182 [CRITICAL] CWE-287 GHSA-p83j-mxpw-gqpj: May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this
VulDB
Cisco Catalyst SD-WAN Manager up to 20.3.2 improper authentication (cisco-sa-sdwan-rpa2-v69WY2SW)
vuldb·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco Catalyst SD-WAN Manager up to 20.3.2 improper authentication (cisco-sa-sdwan-rpa2-v69WY2SW)
A vulnerability has been found in Cisco Catalyst SD-WAN Manager and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-20182. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The affected component should be upgraded.
VulnCheck
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
vulncheck·2026·CVSS 10.0
CVE-2026-20182 [CRITICAL] CWE-287 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Affected: Cisco Catalyst SD-WAN
Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Exploitation References: https://blog.talosinte
No detection rules found.
Metasploit
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
metasploit·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
This module exploits an authentication bypass vulnerability (CVE-2026-20182) in the Cisco Catalyst SD-WAN Controller. The vdaemon DTLS control-plane service performs no certificate or credential verification for connecting peers that claim to be a vHub (device type 2). The vbond_proc_challenge_ack() function implements device-type-specific verification through a series of conditional blocks, but contains no code path for device type 2 (vHub). After a DTLS handshake using any self-signed certificate, an attacker sends a CHALLENGE_ACK (msg_type=9) with the vHub device type encoded in the protocol header. The function falls through all verification checks and unconditionally sets peer->authenticated = 1. This module leverages the au
Nuclei
Cisco Catalyst SD-WAN Controller - vHub Authentication Bypass
nuclei·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco Catalyst SD-WAN Controller - vHub Authentication Bypass
Cisco Catalyst SD-WAN Controller - vHub Authentication Bypass
Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass caused by improper peering authentication mechanism, letting unauthenticated remote attackers obtain administrative privileges, exploit requires sending crafted requests.
Template:
id: CVE-2026-20182
info:
name: Cisco Catalyst SD-WAN Controller - vHub Authentication Bypass
author: sfewer-r7,Crypto-Cat,pussycat0x,DhiyaneshDk
severity: critical
description: |
Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass caused by improper peering authentication mechanism, letting unauthenticated remote attackers obtain administrative privileges, exploit requires sending crafted requests.
remediation: |
Update to the latest fixed versi
Hackernews
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
blogs_hackernews·2026-06-25·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant.
The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges by supplying a crafted file to the affected system by taking advantage of the device's insufficient validation of user-supplied input.
Earlier this month, Cisc
Bleepingcomputer
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
blogs_bleepingcomputer·2026-06-24·CVSS 10.0
CVE-2026-20245 [CRITICAL] Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
## Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
## Lawrence Abrams
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices.
The CVE-2026-20245 vulnerability is a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond) that allows authenticated attackers to execute arbitrary commands as root by uploading a crafted file.
Cisco said the vulnerability stemmed from insufficient validation of user-supplied input and could be exploited by authenticated attackers with local access to affected devices.
When Cisco disclosed the flaw earlier this month, the company warned
Hackernews
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
blogs_hackernews·2026-06-16·CVSS 6.5
CVE-2026-20262 [MEDIUM] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-20262 , carries a CVSS score of 6.5 out of 10.0.
"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system," Cisco said in an advisory.
The issue, the networking equipment company added, stems from inadequat
Bleepingcomputer
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
blogs_bleepingcomputer·2026-06-15·CVSS 6.5
CVE-2026-20262 [MEDIUM] Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
## Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
## Sergiu Gatlan
Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges.
Formerly known as SD-WAN vManage, this network management software allows admins to manage up to 6,000 SD-WAN devices from a single dashboard.
The now-patched zero-day security flaw affects all deployment types, regardless of device configuration, including on-prem deployments, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
Cisco said the issue stems from insufficient validation of user-supplied input during file uploads, which can allow low-privilege remote attackers
Hackernews
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
blogs_hackernews·2026-06-06·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked as CVE-2026-20245 , carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -
On-Prem Deployment
Cisco SD-WAN Cloud-Pro
Cisco SD-WAN Cloud (Cisco Managed)
Cisco SD-WAN for Government (FedRAMP)
"A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary co
Bleepingcomputer
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
blogs_bleepingcomputer·2026-06-05·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco warns of unpatched SD-WAN zero-day exploited in attacks
## Cisco warns of unpatched SD-WAN zero-day exploited in attacks
## Sergiu Gatlan
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245 ) actively exploited in attacks enabling root privilege escalation.
The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).
In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root.
"An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the atta
Rapid7
CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation
blogs_rapid7·2026-06-01·CVSS 9.2
CVE-2026-0826 [CRITICAL] CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation
One of the more persistent myths in security is that old bug classes become old problems. They don’t. They just show up in different places, under different conditions, and usually at the exact moment we’ve convinced ourselves not to pay attention to them.
That’s part of what makes enterprise voice infrastructure so interesting.
Earlier this year, we wrote about a critical vulnerability in Grandstream VoIP phones that showed how easily a trusted communications device could become something very different. It wasn't especially flashy, but it reinforced the broader issue that phones are still part of the attack surface, even if many organizations don’t model them that way.
Today, we'll again discuss the same uncomfortable reality. VoIP technology may sit quietly on a desk and look like a
Rapid7
CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)
blogs_rapid7·2026-06-01·CVSS 9.2
CVE-2026-0826 [CRITICAL] CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)
## Overview
Rapid7 Labs conducted a zero-day research project against an HP Poly VVX 450 Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-0826. A remote attacker can leverage CVE-2026-0826 to achieve unauthenticated remote code execution (RCE) with root privileges on a target device.
The vulnerability is present in the device's parsing of Session Description Protocol (SDP) attributes for Interactive Connectivity Establishment (ICE). The ICE feature, which is not enabled by default, must be enabled for the device to be exploitable by a remote attacker.
While we discovered and validated the vulnerability on a VVX 450 device, the vulnerability has been confirmed to affect all
Rapid7
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
blogs_rapid7·2026-05-28
CVE-2024-39933 Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
## Overview
Rapid7 Labs discovered a critical argument injection ( CWE-88 ) vulnerability in Gogs , a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as CVSSv4 9.4 (Critical). The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the server by creating a pull request with a malicious branch name that injects the --exec flag into git rebase during the "Rebase before merging" merge operation. At the time of publication, the vendor has not released a patch.
The exploit requires no admin privileges and no interaction with other users; an attacker operates entirely within their own account. Since Gogs ships with open registration enabled by default ( DISABLE_REGISTRATION = false ) and no limit on repository creation ( MAX_
Hackernews
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
blogs_hackernews·2026-05-22·CVSS 10.0
CVE-2026-20223 [CRITICAL] Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data.
Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints.
"An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint," Cisco said . "A successful exploit could allow the attacker to read sensitive information and make configuration
Rapid7
Metasploit Wrap Up 05/22/2026
blogs_rapid7·2026-05-22·CVSS 9.8
CVE-2026-20182 [CRITICAL] Metasploit Wrap Up 05/22/2026
## Another week, another authentication bypass
Our humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for CVE-2026-20182, a vulnerability gracing the Cisco Catalyst SD-WAN Controller. The devices, whose purpose is to control a software-defined (SD) wide-area-network (WAN) was unfortunately missing an extra A for authentication. An oversight that Cisco has duly patched.
Elsewhere this week, the HUSTOJ online judge platform has been caught failing to judge its own zip files (CVE-2026-24479), courtesy of a zip-slip RCE module from LoTuS and friends. Next, @Alpenlol has weaponized the small matter of Barracuda's Emai
Rapid7
Q1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement
blogs_rapid7·2026-05-21
CVE-2026-20182 Q1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement
The first quarter of 2026 reinforced that attackers are moving faster, operating with greater coordination, and exploiting weaknesses before most organizations can respond effectively. From escalating geopolitical tensions to increasingly aggressive ransomware operations, the latest quarterly Threat Landscape Report highlights a security environment where reactive defense strategies are becoming unsustainable.
## Quarterly Threat Landscape Report findings
## Exploits unseat social engineering for top initial access vector (IAV)
One of the biggest takeaways is that vulnerability exploitation surpassed social engineering as the largest initial access vector with 38% of the total. This would be interesting on its own, but when coupled with more than 50% of all exploited vulnerabilities act
Bleepingcomputer
Max severity Cisco Secure Workload flaw gives Site Admin privileges
blogs_bleepingcomputer·2026-05-21·CVSS 10.0
CVE-2026-20223 [CRITICAL] Max severity Cisco Secure Workload flaw gives Site Admin privileges
## Max severity Cisco Secure Workload flaw gives Site Admin privileges
## Sergiu Gatlan
Cisco has released security updates to address a maximum-severity Secure Workload vulnerability that allows attackers to gain Site Admin privileges.
Formerly known as Cisco Tetration, Cisco Secure Workload helps admins reduce their network's attack surface through zero trust microsegmentation and stop lateral movement to keep business applications safe.
Tracked as CVE-2026-20223 , the security flaw was found in Secure Workload's internal REST APIs, and it enables unauthenticated attackers to access resources with the privileges of the Site Admin role.
"This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerabil
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Checkpoint
18th May – Threat Intelligence Report
blogs_checkpoint·2026-05-18·CVSS 8.4
CVE-2026-44112 [HIGH] 18th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that customer data and core network infrastructure were not affected by the incident.
Cryptocurr
Hackernews
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
blogs_hackernews·2026-05-15·CVSS 5.4
CVE-2026-20182 [MEDIUM] CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026.
The vulnerability is a critical authentication bypass tracked as CVE-2026-20182 . It's rated 10.0 on the CVSS scoring system, indicating maximum severity.
"Cisco Catalyst SD-WAN Controller and Manager contain an authentication bypass vulnerability
Rapid7
The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers
blogs_rapid7·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers
Imagine you build a massive corporate campus with every security control money can buy. Blast resistant doors. Biometric scanners. Guards at every entrance. Maybe something similar to the infamous Death Star. On paper, it looks fantastic. Then, somewhere along the way, somebody decides the maintenance team needs a universal key that opens every door in the building without setting off any alarms.
That certainly makes operations easier, but it also means one mistake, one compromise (like a well placed photon torpedo), or one very bad decision can unravel the whole thing.
That is basically the problem we keep running into in modern enterprise networking.
## Why SD-WAN controllers create concentrated risk
This week, Rapid7 researchers Stephen Fewer and Jonah Burgess disclosed CVE-2026-201
Hackernews
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
blogs_hackernews·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks.
The vulnerability, tracked as CVE-2026-20182 , carries a CVSS score of 10.0.
"A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system," C
Tenable
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
blogs_tenable·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2
Bleepingcomputer
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
blogs_bleepingcomputer·2026-05-14·CVSS 10.0
CVE-2026-20182 [CRITICAL] Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
## Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
## Lawrence Abrams
Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices.
CVE-2026-20182 has a maximum severity of 10.0 and impacts Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager in on-prem and SD-WAN Cloud deployments.
In an advisory published today, Cisco said the issue stems from a peering authentication mechanism that "is not working properly."
"This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by
Talos
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
blogs_talos·2026-05-14·CVSS 5.4
CVE-2026-20182 [MEDIUM] Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
## Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Cisco Talos is tracking the active exploitation of CVE-2026-20182 , an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.
Successful exploitation of CVE-2026-20182 allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
The exploitation of CVE-2026-20182 appears to have been limited so far and Talos clusters this activity under UAT-8616 with high confidence.
Talos is also aware of a series of threat actors, distinct from UAT-8616, that have been observed to be exploiting a different, previously disclosed set of vulnerabilities, in a new way than p
Rapid7
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
blogs_rapid7·2026-05-14·CVSS 10.0
CVE-2026-20127 [CRITICAL] CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
## Overview
While researching a critical authentication bypass vulnerability, CVE-2026-20127 , which was exploited in-the-wild , Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182 .
This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346), which is the same service that was vulnerable to CVE-2026-20127. The new vulnerability is not a patch bypass of CVE-2026-20127. It is a different issue located in a similar part of the “vdaemon” networking stack.
This impact however is the same, a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations , such as inj
2026-05-14
Published
2026-05-14
Added to CISA KEV
Exploited in the wild