Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco warned that CVE-2026-20182, a critical authentication bypass in Catalyst SD-WAN Controller and Manager, was actively exploited in zero-day attacks to gain administrative access. The flaw can let attackers register rogue peers, manipulate SD-WAN network configuration, and deepen access within affected environments. #CVE-2026-20182 #Cisco #CatalystSDWAN #CISA #Rapid7 #UAT-8616

Keypoints

  • CVE-2026-20182 is a 10.0-severity authentication bypass flaw in Cisco Catalyst SD-WAN products.
  • Attackers used the bug in zero-day attacks to gain high-privileged access on compromised devices.
  • The flaw could allow rogue peer registration and malicious manipulation of SD-WAN fabric routing.
  • Cisco says the issue has no full workaround and must be fixed by upgrading to a patched release.
  • CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal patching.

Read More: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/