Cisco warned that CVE-2026-20182, a critical authentication bypass in Catalyst SD-WAN Controller and Manager, was actively exploited in zero-day attacks to gain administrative access. The flaw can let attackers register rogue peers, manipulate SD-WAN network configuration, and deepen access within affected environments. #CVE-2026-20182 #Cisco #CatalystSDWAN #CISA #Rapid7 #UAT-8616
Keypoints
- CVE-2026-20182 is a 10.0-severity authentication bypass flaw in Cisco Catalyst SD-WAN products.
- Attackers used the bug in zero-day attacks to gain high-privileged access on compromised devices.
- The flaw could allow rogue peer registration and malicious manipulation of SD-WAN fabric routing.
- Cisco says the issue has no full workaround and must be fixed by upgrading to a patched release.
- CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal patching.