Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Public Sector Action Security Patch Release

Cisco SD-WAN CVE-2026-20182 Exploitation, Patching, and KEV Response

Updated 15.05.2026 08:28
Case score 63
Members 4 First seen 05.03.2026 14:15 Latest activity 15.05.2026 08:28

Overview

Active exploitation of **CVE-2026-20182** has put **Cisco Catalyst SD-WAN Controller** and **Cisco Catalyst SD-WAN Manager** at risk of unauthenticated high-privilege access and management-plane tampering. Cisco released fixes after detecting exploitation in May and said no workaround fully mitigates the flaw. The picture sits within a wider **Catalyst SD-WAN** exploitation pattern after Cisco had already confirmed March exploitation of **CVE-2026-20128** and **CVE-2026-20122**, with chaining behavior noted but campaign overlap left unconfirmed. **CISA** has since added **CVE-2026-20182** to the **Known Exploited Vulnerabilities** catalog and set a **May 17, 2026** federal remediation deadline.
Latest development Open development history 3 earlier developments Cisco warns on CVE-2026-20182 and response actions Cisco warned that CVE-2026-20182 is a critical authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager that was being actively exploited in zero-day attacks and could grant administrative privileges, access NETCONF, and allow manipulation of SD-WAN network configuration. Cisco said security updates are available and that upgrading to a fixed software release is the only full remediation, while CISA added the flaw to the Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch affected devices by May 17, 2026.
  1. Earlier development

    Cisco attributes active exploitation to UAT-8616

    Cisco attributed active exploitation of CVE-2026-20182 with high confidence to UAT-8616, the same cluster linked to CVE-2026-20127, and said the actor attempted to add SSH keys, modify NETCONF configurations, and escalate to root privileges after compromise.

  2. Earlier development

    CISA adds CVE-2026-20182 to the KEV catalog

    CISA added CVE-2026-20182, a critical authentication bypass in Cisco Catalyst SD-WAN Controller and Manager that can let a remote unauthenticated attacker obtain administrative privileges, to the KEV catalog and required Federal Civilian Executive Branch agencies to remediate the vulnerability by May 17, 2026.

  3. Earlier development

    Cisco confirms active exploitation of two Catalyst SD-WAN vulnerabilities

    Cisco updated its advisory to say it had become aware of active exploitation of CVE-2026-20128 in the Data Collection Agent (DCA) feature of Catalyst SD-WAN Manager and CVE-2026-20122 in the manager API. Cisco said the attacks appear to have been chained with other flaws, but it did not share attack details.

Signals

Exploitation
CVEs/products
Remediation
Status
Threat context

Threat actor context

2 listed

Malware & tooling context

4 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)
Updated 14.05.2026 23:09 Lead Contribution 60
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**CVE-2026-20182** is an actively exploited **authentication bypass** in **Cisco Catalyst SD-WAN Controller** and **Cisco Catalyst SD-WAN Manager**, creating a path to **administrative privileges** and SD-WAN configuration tampering. Cisco said it detected exploitation in **May** and released **security updates** to fully remediate the issue. CISA added the flaw to the **Known Exploited Vulnerabilities Catalog**, setting a **May 17, 2026** patch deadline for federal agencies.

Exploitation Wave Cisco Catalyst SD-WAN active exploitation wave
Updated 05.03.2026 14:15 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**Cisco** confirmed **active exploitation** of **two recently patched Catalyst SD-WAN vulnerabilities**, creating immediate risk for exposed systems that have not been fully remediated. The affected flaws are **CVE-2026-20128** and **CVE-2026-20122**. Cisco said the attacks appear to involve **chaining with other flaws**, which can increase the chance of privilege escalation and deeper system compromise. The company also said it is **unclear whether the exploits are part of the same campaign** or separate operations.

Public Sector Action CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182
Updated 15.05.2026 08:28 Context
Policy Stage Enforced

**CISA** added **CVE-2026-20182** to the **KEV catalog** and ordered **Federal Civilian Executive Branch agencies** to remediate **Cisco Catalyst SD-WAN Controller** by **May 17, 2026**, turning the flaw into a federal remediation priority because it is tied to active abuse. The move puts a concrete deadline on federal response and raises urgency around affected **Cisco SD-WAN** environments. It also reinforces the operational significance of the vulnerability for government networks.

Security Patch Release Cisco security patch release for CVE-2026-20182
Updated 14.05.2026 20:45 Context
Exploitation Active Exploitation CVSS 10.0 Critical Urgency Immediate Patch Patch Available

Cisco released **updates** for **CVE-2026-20182**, a **maximum-severity authentication bypass** in **Catalyst SD-WAN Controller/Manager**, after the flaw was **exploited in limited attacks**. The patch applies to affected **on-prem**, **Cloud-Pro**, **Cloud (Managed)**, and **FedRAMP** deployments. Cisco urged customers to install the **latest updates** as soon as possible because **internet-exposed systems** face higher compromise risk.