• News/
  • darkreading-20260514202531

Maximum Severity Cisco SD-WAN Bug Exploited in the Wild

Dark Reading
·
Nate Nelson
·
Published May 14, 2026
·
Updated

A highly sophisticated threat actor is exploiting a critical vulnerability in Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) Controllers. Rapid7 disclosed CVE-2026-20182, an authentication bypass vulnerability in Cisco's market-leading network management solution. By allowing unauthenticated attackers free rein over one of an organization's most powerful tools, it earned the highest possible 10 out of 10 score in the Common Vulnerability Scoring System (CVSS). In an updated blog post today, Rapid7 director of vulnerability intelligence Douglas McKee hammered home just how serious an issue this was. "Attackers have become very good at turning central infrastructure weaknesses into high impact operations," he warned, and for nation-states in particular, "an SD-WAN controller is a great place to do [espionage], because it lives in the middle of trust relationships most organizations rarely question." To avoid sensationalizing, McKee added, "To be fair, not every bug turns into Internet-wide exploitation overnight." In fact, CVE-2026-20182 had been exploited overnight. In a separate publication that same day, researchers at Cisco Talos flagged that a group it tracks as UAT-8616 has already gotten to it. Not only is CVE-2026-20182 not the first vulnerability discovered in Cisco Catalyst this year, it isn't even the first authentication bypass vulnerability with a "critical" 10 score on the CVSS scale. Back in February, Cisco revealed half a dozen issues with Catalyst. ...

Read full article

Affected Software

3 affected components
Cisco Catalyst SD-WAN Controller
Cisco Catalyst Controller
Cisco Catalyst Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical vulnerability in Cisco SD-WAN Controllers.

2

What specific vulnerability is highlighted in this article?

The article highlights CVE-2026-20182, an authentication bypass vulnerability in Cisco's software.

3

Which products are affected by this security vulnerability?

The affected products include the Cisco Catalyst SD-WAN Controller, Catalyst Controller, and Catalyst Manager.

4

What actions should organizations take regarding this vulnerability?

Organizations using the affected Cisco products should urgently apply any available patches and updates.

5

Who disclosed the vulnerability and its exploitation?

The vulnerability and the details of its exploitation were disclosed by Rapid7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203