CVE-2026-20182Active Exploitation(cisco / catalyst_sd-wan_manager)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 98 mentions and remains active

Immediate actions

  • Patch cisco catalyst_sd-wan_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.  A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-17. Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager
  • sd-wan_vbond_orchestrator
  • sd-wan_vsmart_controller

Threat summary

  • Active exploitation appears in 219 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 303 mentions across 44 observed days

What's happening

  • Active exploitation reported across 219 signals
  • Exploit tool or code specified in 13 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 115 signals
  • Technical details provided in 209 signals
  • Disclosure: 37 classified signals
  • Peaked 42d ago at 98 mentions (2026-05-15); latest day: 1
  • 303 total mentions across 44 days

Affected systems

Vendors
Products
catalyst_sd-wan_managersd-wan_vbond_orchestratorsd-wan_vsmart_controller

1 version affected across 3 products

Deep dive

Activity timeline303 mentions / 44d
025497498Mentions · 2026-05-14: 30Mentions · 2026-05-15: 98Mentions · 2026-05-16: 25Mentions · 2026-05-17: 18Mentions · 2026-05-18: 27Mentions · 2026-05-19: 23Mentions · 2026-05-20: 14Mentions · 2026-05-21: 5Mentions · 2026-05-22: 8Mentions · 2026-05-23: 4Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-26: 2Mentions · 2026-05-27: 1Mentions · 2026-05-28: 2Mentions · 2026-05-29: 1Mentions · 2026-05-31: 3Mentions · 2026-06-01: 1Mentions · 2026-06-05: 5Mentions · 2026-06-06: 3Mentions · 2026-06-07: 3Mentions · 2026-06-08: 1Mentions · 2026-06-09: 2Mentions · 2026-06-11: 3Mentions · 2026-06-12: 1Mentions · 2026-06-15: 3Mentions · 2026-06-19: 1Mentions · 2026-06-23: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Mentions · 2026-07-06: 1Mentions · 2026-07-11: 1Mentions · 2026-07-12: 1Mentions · 2026-07-17: 1Mentions · 2026-07-22: 1Mentions · 2026-07-27: 1Mentions · 2026-08-02: 1Mentions · 2026-08-03: 1Mentions · 2026-08-05: 1Mentions · 2026-08-14: 1Mentions · 2026-09-27: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-05-14: 2PoC Mentioned / Linked · 2026-05-15: 3PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-18: 2PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-22: 4PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-28: 2PoC Mentioned / Linked · 2026-06-05: 1Exploit Tool / Code · 2026-05-14: 2Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-18: 2Exploit Tool / Code · 2026-05-22: 4Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-05-26: 1Exploit Tool / Code · 2026-05-28: 1Exploit Tool / Code · 2026-06-05: 1Active Exploitation · 2026-05-14: 22Active Exploitation · 2026-05-15: 82Active Exploitation · 2026-05-16: 18Active Exploitation · 2026-05-17: 10Active Exploitation · 2026-05-18: 18Active Exploitation · 2026-05-19: 15Active Exploitation · 2026-05-20: 11Active Exploitation · 2026-05-21: 4Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-23: 2Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-05-31: 1Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-06-05: 3Active Exploitation · 2026-06-06: 2Active Exploitation · 2026-06-07: 3Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-09: 2Active Exploitation · 2026-06-11: 3Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-15: 3Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-27: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-05: 1Patch / Workaround · 2026-05-14: 8Patch / Workaround · 2026-05-15: 36Patch / Workaround · 2026-05-16: 11Patch / Workaround · 2026-05-17: 7Patch / Workaround · 2026-05-18: 13Patch / Workaround · 2026-05-19: 7Patch / Workaround · 2026-05-20: 5Patch / Workaround · 2026-05-21: 3Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-05: 3Patch / Workaround · 2026-06-06: 2Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-09: 2Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-05-14: 23Technical Details · 2026-05-15: 58Technical Details · 2026-05-16: 19Technical Details · 2026-05-17: 14Technical Details · 2026-05-18: 17Technical Details · 2026-05-19: 15Technical Details · 2026-05-20: 10Technical Details · 2026-05-21: 4Technical Details · 2026-05-22: 8Technical Details · 2026-05-23: 2Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 1Technical Details · 2026-05-28: 2Technical Details · 2026-05-29: 1Technical Details · 2026-05-31: 2Technical Details · 2026-06-01: 1Technical Details · 2026-06-05: 4Technical Details · 2026-06-06: 3Technical Details · 2026-06-07: 2Technical Details · 2026-06-09: 2Technical Details · 2026-06-11: 2Technical Details · 2026-06-12: 1Technical Details · 2026-06-15: 3Technical Details · 2026-06-19: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-12: 1Technical Details · 2026-08-02: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-05: 105-1405-1805-2205-2605-3106-0706-1206-2507-0607-2208-0509-30
Signal classification6 categories
Active Exploitation
20367.4%
Patch
3812.6%
Disclosure
3712.3%
General
144.7%
Exploit
82.7%
PoC
10.3%
Referenced assets176 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-1430
Active Exploitation21Disclosure5Exploit1General1Patch2
2026-05-1598
Active Exploitation75Disclosure9General2Patch12
2026-05-1625
Active Exploitation15Disclosure4General2Patch4
2026-05-1718
Active Exploitation9Disclosure5General1Patch3
2026-05-1827
Active Exploitation17Disclosure4Exploit1General1Patch4
2026-05-1923
Active Exploitation14Disclosure4General3Patch2
2026-05-2014
Active Exploitation11Disclosure2Patch1
2026-05-215
Active Exploitation4Patch1
2026-05-228
Active Exploitation1Disclosure2Exploit4Patch1
2026-05-234
Active Exploitation2Exploit1Patch1
2026-05-241
Active Exploitation1
2026-05-251
Patch1
2026-05-262
General1PoC1
2026-05-271
Active Exploitation1
2026-05-282
Active Exploitation1Disclosure1
2026-05-291
Active Exploitation1
2026-05-313
Active Exploitation1General1Patch1
2026-06-011
Active Exploitation1
2026-06-055
Active Exploitation3Exploit1Patch1
2026-06-063
Active Exploitation2Patch1
2026-06-073
Active Exploitation3
2026-06-081
Active Exploitation1
2026-06-092
Active Exploitation2
2026-06-113
Active Exploitation3
2026-06-121
Active Exploitation1
2026-06-153
Active Exploitation2Disclosure1
2026-06-191
Active Exploitation1
2026-06-231
Active Exploitation1
2026-06-251
Active Exploitation1
2026-06-261
Active Exploitation1
2026-06-271
Active Exploitation1
2026-07-021
Active Exploitation1
2026-07-061
Patch1
2026-07-111
Active Exploitation1
2026-07-121
Active Exploitation1
2026-07-171
General1
2026-07-221
General1
2026-07-271
Active Exploitation1
2026-08-021
Patch1
2026-08-031
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-141
Patch1
Full discourse20 posts
  • Stephen Fewer@stephenfewer
    Active Exploitation

    Today @rapid7 and Cisco are disclosing CVE-2026-20182, a critical (CVSS 10.0) auth bypass affecting Cisco Catalyst SD-WAN Controller, found by @_CryptoCat and I when we were researching CVE-2026-20127 last Feb. An unauth attacker can become the vmanage-admin and issue arbitrary NETCONF commands. Cisco has also disclosed that the new CVE is already EITW as of this month. Read our blog here with full technical details: https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/

    Post summary

    Rapid7 and Cisco jointly disclose CVE‑2026‑20182, a CVSS‑10 critical authentication bypass in Cisco Catalyst SD‑WAN Controller, which is already being exploited in the wild, though no PoC or exploit code is provided.

    790628611771.6K
    9.8K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Limited attacks are exploiting CVE-2026-20182, a CVSS 10.0 auth bypass in Cisco Catalyst SD-WAN Controller. Unauthenticated remote attackers can gain admin privileges and manipulate SD-WAN configurations. Affected: on-prem, cloud, government deployments. Full details and mitigation steps: https://thehackernews.com/2026/05/cisco-catalyst-sd-wan-controller-auth.html

    Post summary

    CVE-2026-20182 is actively being exploited in limited attacks, enabling unauthenticated attackers to gain admin privileges on Cisco Catalyst SD-WAN Controllers; mitigation steps are provided.

    36872024525.4K
    1.9M followersView on X
  • Rapid7@rapid7
    Disclosure

    🚨 Rapid7 Labs has discovered an authentication bypass vuln. affecting #Cisco Catalyst SD-WAN Controller (FKA vSmart). CVE-2026-20182 has a Critical CVSSv3.1 score of 10.0 and allows a remote unauth. attacker to perform privileged operations. Read on: https://r-7.co/4uLxSlR https://t.co/bM98tovvut

    Post summary

    Rapid7 Labs disclosed a critical authentication bypass (CVE-2026-20182) in Cisco Catalyst SD‑WAN Controller, enabling remote unauthenticated privileged actions and scoring 10.0 on CVSS v3.1. No PoC, exploit, patch, or active exploitation details are provided.

    34561182924.1K
    124.6K followersView on X
  • CryptoCat@_CryptoCat
    Active Exploitation

    CVE-2026-20182 is already confirmed active in the wild. We've expedited the release of the @metasploit module 💥

    Post summary

    CVE‑2026‑20182 has been confirmed actively exploited in the wild, and a Metasploit module has been released to facilitate exploitation.

    0110914016.9K
    8.9K followersView on X
  • 0xor0ne@0xor0ne
    Patch

    Cisco Catalyst SD-WAN Controller auth bypass (CVE-2026-20182) https://rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/ #infosec https://t.co/GDQToCY11r

    Post summary

    Rapid7 blog discusses CVE‑2026‑20182, an authentication bypass in Cisco Catalyst SD‑WAN Controller, noting that the vulnerability has been fixed by the vendor.

    112072308.5K
    93.5K followersView on X
  • 0xor0ne@0xor0ne
    Patch

    CVE-2026-20182: Cisco Catalyst SD-WAN Controller auth bypass https://rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/ #infosec https://t.co/vA4QA7LHCH

    Post summary

    The tweet links to a Rapid7 post about CVE‑2026‑20182, an authentication bypass in Cisco Catalyst SD‑WAN Controller, and indicates the issue has been fixed.

    113072285.4K
    94.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 CISA added CVE-2026-20182, a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller, to its KEV catalog amid active exploitation. Remote attackers can gain admin privileges. FCEB agencies must remediate by May 17, 2026. Full details: https://thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html

    Post summary

    CISA added CVE‑2026‑20182 to its KEV catalog due to active exploitation, noting a CVSS 10.0 authentication bypass that allows remote attackers to gain admin rights; no patch or PoC details are disclosed.

    022177910.9K
    1.9M followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Cisco Catalyst SD-WAN Controller auth bypass in vdaemon DTLS via spoofed vHub device type (CVE-2026-20182) https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/ #infosec https://t.co/XjxHQBp2Nd

    Post summary

    Rapid7 reports a new authentication bypass (CVE‑2026‑20182) in Cisco Catalyst SD‑WAN Controller caused by spoofed vHub device types in DTLS, and Cisco has issued a fix.

    215064255.8K
    92.2K followersView on X
  • 0xor0ne@0xor0ne

    Cisco Catalyst SD-WAN Controller auth bypass (CVE-2026-20182) https://rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/ #cybersecurity https://t.co/LPp3wSksOZ

    07042294.5K
    94.3K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Cisco Catalyst SD-WAN controller authentication bypass vulnerability CVE-2026-20182 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/W5LPQtCaez

    Post summary

    The message announces that CVE-2026-20182, an authentication bypass in Cisco Catalyst SD‑WAN controller, has been detected as actively exploited and is listed in the DHS Known Exploited Vulnerabilities Catalog.

    31815057.9K
    300.1K followersView on X
  • nekono_nanomotoni@nekono_naha
    Active Exploitation

    CVE-2026-20182 affects Cisco Catalyst SD-WAN vdaemon DTLS control plane (UDP/12346). Rapid7’s chain uses TCP/830 as NETCONF over SSH after auth bypass. My scan: 460 public hosts responded on UDP/12346; 277 also exposed TCP/830 on the same IP. Image: country breakdown. https://t.co/KYBkpt5Jfv

    Post summary

    Rapid7 has identified an exploitation chain for CVE-2026-20182 in Cisco SD‑WAN vdaemon, with hundreds of publicly exposed devices on UDP/12346 and TCP/830 indicating active exploitation in the wild.

    213131129.7K
    6.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation https://darkwebinformer.com/cve-2026-20182-critical-cisco-sd-wan-auth-bypass-under-active-exploitation/

    Post summary

    The post announces that CVE‑2026‑20182, a Cisco SD‑WAN authentication bypass, is being actively exploited in the wild.

    1303935.6K
    223.7K followersView on X
  • CryptoCat@_CryptoCat
    Disclosure

    Quick video about the new SD-WAN Auth bypass (CVE-2026-20182) discovered by @Rapid7 Labs 👀 I say quick, because @stephenfewer will be joining @fulmetalpackets and myself to talk all about it (and more) in the next podcast - dropping Thursday 🔥 https://youtu.be/_AxRbX_GLiA

    Post summary

    The tweet announces a newly discovered SD‑WAN authentication bypass (CVE‑2026‑20182) and references a forthcoming podcast, but lacks technical details, exploitation evidence, or mitigation information.

    0702772.6K
    8.9K followersView on X
  • Co11ateral@co11ateral
    Exploit

    CVE-2026-20182 (10 CVSS) Authentication bypass in Cisco Catalyst SD-WAN Controller vHub. One more thing to be aware of this month. https://github.com/rapid7/metasploit-framework/pull/21463 #dfir #redteam

    Post summary

    The post announces CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Controller vHub, and links to a Metasploit pull request that supplies a functional exploit.

    1702171.4K
    8.9K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Explotan vulnerabilidad de salto de autenticación en Cisco Catalyst SD-WAN Controller para obtener acceso de administrador Cisco lanzó actualizaciones para corregir una vulnerabilidad crítica (CVE-2026-20182) en Catalyst SD-WAN https://blog.elhacker.net/2026/05/explotan-vulnerabilidad-de-salto-de.html

    Post summary

    The article reports that the authentication bypass CVE-2026-20182 in Cisco Catalyst SD‑WAN Controller is being actively exploited for admin access, and Cisco has released patches to address it.

    0602462.4K
    141.0K followersView on X
  • Azubuike Ibe@ai_dev_official
    Active Exploitation

    Cisco has disclosed CVE-2026-20245. The 7th SD-WAN zero-day exploited in 2026. Seven in one year. That is not bad luck. That is a pattern. This one hits Cisco Catalyst SD-WAN Manager and lets an attacker execute commands as root on the management system. Earlier 2026 flaws like CVE-2026-20127 and CVE-2026-20182 enabled full authentication bypass and remote admin access. Attackers have been chaining these. A compromised SD-WAN controller is not just a network problem. It hands attackers policy manipulation, route changes, rogue peer insertion, and persistence. Your backend does not need to be the direct target. The management plane gets breached and everything downstream is exposed. Here is what makes this worse. When Cisco disclosed CVE-2026-20245, a patch was not yet available. Patching is still the goal. But right now, the priorities are different. Restrict management-plane access immediately. Segment SD-WAN management networks hard. Enforce least privilege on every account touching the controller. Monitor continuously for anomalous admin activity and unauthorised peers. Treating SD-WAN as set-and-forget infrastructure in 2026 is not a posture. It is a liability. My name is Azubuike Ibe and I write about threats that are already inside the perimeter while most teams are still watching the edge. Share this with the backend or network engineer on your team who still thinks SD-WAN management is a low-risk surface. #Cybersecurity #Cisco #SDWAN #ZeroDay #DevSecOps #NetworkSecurity

    Post summary

    Cisco disclosed CVE-2026-20245, a root‑execution flaw in its SD‑WAN Manager, with evidence of active exploitation and no patch yet available, prompting immediate hardening and monitoring measures.

    0409889
    1.5K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-20182: Unauthenticated Cisco SD-WAN Control-Plane Compromise via vHub Authentication Bypass https://www.resecurity.com/blog/article/cve-2026-20182-unauthenticated-cisco-sd-wan-control-plane-compromise-via-vhub-authentication-bypass

    Post summary

    The provided text announces a new Cisco SD-WAN vulnerability (CVE-2026-20182) that allows unauthenticated attackers to bypass vHub authentication and compromise the control plane, with a link to a detailed blog article.

    0301521.9K
    158.6K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Critical CVSS 10 flaw CVE-2026-20182 allows full hijacking of Cisco Catalyst SD-WAN Controllers. Threat actors are actively exploiting it—patch immediately. https://securityexpress.info/unauthenticated-cvss-10-flaw-sparking-full-hijacking-of-cisco-sd-wan-controllers/ https://t.co/sBtR0VCIi8

    Post summary

    CVE-2026-20182 is being actively exploited in the wild, allowing full hijacking of Cisco SD‑WAN Controllers, and an immediate patch is urgently required.

    03096824
    12.5K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits http://dlvr.it/TTkZ8B #CyberSecurity #Cisco #SDWAN #CVE2026 #Vulnerability https://t.co/5yiQiexNmQ

    Post summary

    CISA added CVE-2026-20182 to the KEV list after evidence of admin‑access exploitation, indicating active attacks are occurring.

    030921.8K
    57.3K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Cisco Catalyst SD-WAN CVE-2026-20182 (CVSS 10) exploited in the wild. Attackers bypassing auth to seize admin control. Upgrade your network fabric now! #Cisco #SDWAN #CyberSecurity #InfoSec #VulnerabilityAlert #CVE202620182 #NetworkSecurity #ExploitAlert https://securityonline.info/cisco-catalyst-sd-wan-vulnerability-cve-2026-20182-exploited-cvss-10/ https://t.co/q4i136yWN8

    Post summary

    The tweet alerts that CVE-2026-20182, a CVSS 10 flaw in Cisco Catalyst SD‑WAN, is actively exploited in the wild, allowing attackers to bypass authentication and gain admin control.

    030110568
    12.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager20.12.7--
Appciscosd-wan_vbond_orchestrator---
Appciscosd-wan_vbond_orchestrator20.12.7--
Appciscosd-wan_vsmart_controller---
Appciscosd-wan_vsmart_controller20.12.7--

Explore more