The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via BleepingComputer

BleepingComputer · track record
69Stories
100%Verified
830d
All sources →
Home/Tech/Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
VERIFIEDBy Xavier Rivera· ·2.5 min read

Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days

Cisco disclosed that CVE-2026-20182, a critical authentication bypass in its Catalyst SD-WAN Controller and Manager, is being actively exploited in zero-day attacks allowing high-privileged access and network configuration manipulation. CISA has added the flaw to its Known Exploited Vulnerabilities Catalog with a patching deadline of May 17, 2026 for federal agencies while Cisco released updates but no full workarounds.

Source:BleepingComputer
Post
Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
TL;DRAI · 60 sec read

Cisco warns of CVE-2026-20182, a critical 10.0-severity authentication bypass in Catalyst SD-WAN Controller and Manager for on-premises and cloud deployments, actively exploited in zero-days. Attackers gain high-privileged access to manipulate configurations via NETCONF and add rogue peers for network control. CISA adds it to Known Exploited Vulnerabilities Catalog, mandating federal patches by May 17, 2026.

Cisco has issued an advisory about a severe authentication bypass vulnerability, identified as CVE-2026-20182, that threat actors have leveraged in zero-day attacks to obtain administrative access on targeted systems.

The flaw carries the highest possible CVSS score of 10.0 and affects both the Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager across on-prem installations as well as SD-WAN Cloud environments. According to the company, the root cause lies in a peering authentication mechanism "that is not working properly." The advisory explains that an attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful compromise reportedly lets the intruder authenticate to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user. From there, the attacker could reach NETCONF functions and alter network settings across the SD-WAN fabric.

Cisco Catalyst SD-WAN functions as a software-defined platform designed to link branch offices, data centers, and cloud resources under centralized management, directing traffic between locations over encrypted tunnels.

The vendor reportedly identified exploitation attempts during May without disclosing specific attack techniques. Indicators of compromise direct administrators to scan SD-WAN Controller logs for signs of unauthorized peering events that might reflect efforts to onboard rogue devices into the fabric. Such rogue peers could enable insertion of attacker-controlled hardware that mimics legitimate nodes, allowing encrypted links and the advertisement of malicious networks to facilitate lateral movement.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Security researchers at Rapid7 uncovered the issue while investigating a separate Cisco SD-WAN controller vulnerability, tracked as CVE-2026-20127, which received a patch in February. That earlier flaw had also been exploited in zero-day operations by a group designated "UAT-8616" since 2023 for the purpose of establishing rogue peers inside victim environments.

Cisco has issued updated software releases that resolve CVE-2026-20182 and stated there are no workarounds capable of completely eliminating the risk. The vendor further advises limiting exposure of SD-WAN management and control-plane interfaces exclusively to trusted internal networks or approved IP ranges, along with routine inspection of authentication logs for anomalous activity.

CISA has placed the Cisco CVE-2026-20182 flaw on its Known Exploited Vulnerabilities Catalog, directing federal agencies to apply fixes no later than May 17, 2026.
Cisco additionally urges organizations with internet-facing Catalyst SD-WAN Controllers to examine logs for evidence of suspicious access or peering attempts, including entries in /var/log/auth.log that contain "Accepted publickey for vmanage-admin" originating from unfamiliar addresses. Any such IP should be cross-checked against authorized System IPs shown in the Cisco Catalyst SD-WAN Manager interface under WebUI > Devices > System IP; mismatched successful logins warrant treating the system as breached and contacting Cisco TAC.

EXPERT TAKE

Administrators should review /var/log/auth.log for "Accepted publickey for vmanage-admin" entries from unknown IPs not matching configured System IPs and restrict management interface access to trusted networks per Cisco's guidance.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CiscoSD-WANVulnerability
More fromBleepingComputer
  • ChainDrop worm compromises over 1,300 npm packages totaling 2 billion downloads

    Tech · 3d
  • Anthropic confirms worldwide Claude outage

    Tech · 9d
  • MCBS breach impacts records of 1.26 million individuals

    Tech · 11d
More inTech
  • Tesla and SpaceX confirm Terafab chip fab in Texas

    Tech · 1d
  • OpenAI Urges Federal Judge to Throw Out Apple's Trade Secrets Complaint

    Tech · 2d
  • Meta introduces Muse Code, its terminal-based coding agent

    Tech · 2d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

MORE IN TECH

Tesla and SpaceX confirm Terafab chip fab in Texas

Tesla and SpaceX have confirmed Grimes County, Texas as the site for their Terafab semiconductor megafactory, with the first phase costing roughly $16.8 billion. The project targets the largest chip manufacturing facility on the planet to supply over 1 terawatt of compute per year that exceeds current and future global production capacity.

OpenAI Urges Federal Judge to Throw Out Apple's Trade Secrets Complaint

OpenAI has filed a motion asking a federal judge to dismiss Apple's trade secrets lawsuit, describing the claims as meritless. The dispute, which follows a July suit and this week's injunction request from Apple, highlights tensions after their prior partnership on Siri and OpenAI's hardware push.

Meta introduces Muse Code, its terminal-based coding agent

Meta has released an early beta of Muse Code, a terminal-based coding agent driven by the updated Muse Spark 1.2 model and positioned against Anthropic's Claude Code and OpenAI's Codex. Substantially lower rates, including a contributor plan at $0.10 for every million tokens received, may encourage migration away from higher-priced options such as Anthropic's Sonnet 5.