The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via BleepingComputer

BleepingComputer · track record
78Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
VERIFIEDBy Xavier Rivera· ·2.5 min read

Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days

Cisco disclosed that CVE-2026-20182, a critical authentication bypass in its Catalyst SD-WAN Controller and Manager, is being actively exploited in zero-day attacks allowing high-privileged access and network configuration manipulation. CISA has added the flaw to its Known Exploited Vulnerabilities Catalog with a patching deadline of May 17, 2026 for federal agencies while Cisco released updates but no full workarounds.

Source:BleepingComputer
Post
Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Cisco warns of CVE-2026-20182, a critical 10.0-severity authentication bypass in Catalyst SD-WAN Controller and Manager for on-premises and cloud deployments, actively exploited in zero-days. Attackers gain high-privileged access to manipulate configurations via NETCONF and add rogue peers for network control. CISA adds it to Known Exploited Vulnerabilities Catalog, mandating federal patches by May 17, 2026.

Cisco has issued an advisory about a severe authentication bypass vulnerability, identified as CVE-2026-20182, that threat actors have leveraged in zero-day attacks to obtain administrative access on targeted systems.

The flaw carries the highest possible CVSS score of 10.0 and affects both the Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager across on-prem installations as well as SD-WAN Cloud environments. According to the company, the root cause lies in a peering authentication mechanism "that is not working properly." The advisory explains that an attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful compromise reportedly lets the intruder authenticate to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user. From there, the attacker could reach NETCONF functions and alter network settings across the SD-WAN fabric.

Cisco Catalyst SD-WAN functions as a software-defined platform designed to link branch offices, data centers, and cloud resources under centralized management, directing traffic between locations over encrypted tunnels.

The vendor reportedly identified exploitation attempts during May without disclosing specific attack techniques. Indicators of compromise direct administrators to scan SD-WAN Controller logs for signs of unauthorized peering events that might reflect efforts to onboard rogue devices into the fabric. Such rogue peers could enable insertion of attacker-controlled hardware that mimics legitimate nodes, allowing encrypted links and the advertisement of malicious networks to facilitate lateral movement.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Security researchers at Rapid7 uncovered the issue while investigating a separate Cisco SD-WAN controller vulnerability, tracked as CVE-2026-20127, which received a patch in February. That earlier flaw had also been exploited in zero-day operations by a group designated "UAT-8616" since 2023 for the purpose of establishing rogue peers inside victim environments.

Cisco has issued updated software releases that resolve CVE-2026-20182 and stated there are no workarounds capable of completely eliminating the risk. The vendor further advises limiting exposure of SD-WAN management and control-plane interfaces exclusively to trusted internal networks or approved IP ranges, along with routine inspection of authentication logs for anomalous activity.

CISA has placed the Cisco CVE-2026-20182 flaw on its Known Exploited Vulnerabilities Catalog, directing federal agencies to apply fixes no later than May 17, 2026.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Cisco additionally urges organizations with internet-facing Catalyst SD-WAN Controllers to examine logs for evidence of suspicious access or peering attempts, including entries in /var/log/auth.log that contain "Accepted publickey for vmanage-admin" originating from unfamiliar addresses. Any such IP should be cross-checked against authorized System IPs shown in the Cisco Catalyst SD-WAN Manager interface under WebUI > Devices > System IP; mismatched successful logins warrant treating the system as breached and contacting Cisco TAC.

EXPERT TAKE

Administrators should review /var/log/auth.log for "Accepted publickey for vmanage-admin" entries from unknown IPs not matching configured System IPs and restrict management interface access to trusted networks per Cisco's guidance.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CiscoSD-WANVulnerability
More fromBleepingComputer
  • Denmark CPR breach exposes data of 8.8 million people

    Tech · 3d
  • Microsoft Rolls Out Windows 11 2026 Update as Small Enablement Package

    Tech · 9d
  • OpenAI confirms GPT-6 Astra reaches Critical cybersecurity threshold

    Tech · 1mo
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 8h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 11h
  • Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Tech · 11h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Cisco Releases Hardening Fix for Critical NX-OS Vulnerability

    Cisco has released NX-OS hardening updates covering CVE-2026-76455, a group of improper access control issues (CWE-284) scored 9.8 critical. Cisco found the issues in an internal review and says they are not known to be exploited.

  • Tech· 

    Cisco releases hardening fixes for critical CVE-2026-76482 in Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem)

    Cisco has released hardening updates for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), to fix CVE-2026-76482, a critical vulnerability with a CVSS score of 10. The flaw stems from improper input verification and was identified during an internal security review.

  • Tech· 

    Critical CVE-2026-76465 Allows Root RCE on Cisco Nexus Switches

    A critical vulnerability tracked as CVE-2026-76465 affects the MPLS OAM feature in Cisco NX-OS on Nexus 3000 and 9000 Series Switches. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges or trigger denial-of-service conditions.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.