Cisco Patches Actively Exploited SD-WAN Zero-Day Vulnerability
Cisco released emergency patches for CVE-2026-20182, a critical zero-day vulnerability in its Catalyst SD-WAN Controller allowing unauthenticated remote administrative access. With a maximum severity score of 10.0, the flaw is being actively exploited by threat group UAT-8616, potentially linked to Chinese espionage. The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch within three days. Experts warn this compromise enables traffic interception and network disruption, urging immediate remediation and log auditing for all affected organizations globally.
Editorial summary awaiting refresh
Cross-source coverage
Wire timeline
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV Catalog Amid Active Exploitation
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20182 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of administrative access flaws in Cisco SD-WAN appliances. This listing serves as a critical prioritization signal for security operations, indicating that attackers are currently leveraging this vulnerability rather than it being a theoretical risk. For federal agencies, this triggers mandatory remediation deadlines under Binding Operational Directive 22-01. The article emphasizes that SD-WAN devices are high-value targets due to their internet-facing nature and central role in network architecture, allowing attackers to intercept traffic and pivot laterally. Security leaders are urged to shift from CVSS-score-based prioritization to KEV-status-based response, treating affected systems as potentially compromised. Recommendations include immediate patching, assuming compromise on exposed appliances, and conducting thorough hunts for post-exploitation indicators. This event aligns with a broader trend of edge device exploitation seen in recent years with Ivanti, Palo Alto, and Fortinet vulnerabilities.
DEV CommunityCisco Zero-Day Vulnerability Under Active Attack by Persistent Threat Group
Cisco has disclosed a critical zero-day vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager, which is currently being exploited in limited attacks. The vulnerability, rated with a maximum CVSS score of 10, allows attackers to bypass authentication and gain full administrative access by impersonating trusted network routers. Rapid7 discovered the flaw in March and reported it to Cisco, which released a patch following confirmation of active exploitation. The attacks are attributed to UAT-8616, a persistent threat group previously linked to other zero-day exploits in Cisco’s firewall and SD-WAN systems over the past three years. This incident adds to a series of recently disclosed vulnerabilities in Cisco’s network edge software, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add the defect to its known exploited vulnerabilities catalog. Experts warn that compromising the SD-WAN controller could allow attackers to influence entire network fabrics, reroute traffic, and intercept communications across connected branches and data centers. Cisco urges customers to apply available patches immediately, while researchers highlight the growing trend of threat groups chaining vulnerabilities for widespread impact on unpatched infrastructure.
CyberScoopCISA Orders Federal Agencies to Patch Critical Cisco SD-WAN Vulnerability by Sunday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that all federal agencies patch a critical vulnerability in Cisco SD-WAN systems by Sunday. The flaw, identified as CVE-2026-20182, was discovered by incident responders at Rapid7 in March while investigating a previous campaign that caused international alarm in February. Cisco released a patch on Thursday, warning that the bug allows unauthenticated remote attackers to bypass authentication and gain administrative privileges. The vulnerability carries a maximum severity score of 10 out of 10, with active exploitation observed recently. CISA requires agencies not only to apply the patch but also to adhere to guidance from a February emergency directive, which includes identifying affected systems, collecting logs, and hunting for compromise evidence. Experts describe the vulnerability as behaving like a master key, allowing attackers to trick controllers into trusting malicious routers. This access is considered ideal for nation-state actors seeking persistent, stealthy presence within networks to observe and influence operations over time. The response involves coordination with Five Eyes intelligence allies, highlighting the severe threat posed by advanced actors targeting critical networking infrastructure.
The Record from Recorded Future NewsCISA Orders Federal Agencies to Patch Critical Cisco SD-WAN Vulnerability by Sunday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that all federal agencies patch a critical vulnerability in Cisco SD-WAN systems by Sunday. The flaw, identified as CVE-2026-20182, was discovered by incident responders at Rapid7 in March while investigating a previous campaign that caused international alarm in February. Cisco released a patch on Thursday, warning that the bug allows unauthenticated remote attackers to bypass authentication and gain administrative privileges. The vulnerability carries a maximum severity score of 10 out of 10, with active exploitation observed recently. CISA requires agencies to not only apply the patch but also adhere to guidance from a February emergency directive, which includes identifying affected systems, collecting logs, and hunting for compromise evidence. Experts describe the vulnerability as behaving like a master key, allowing attackers to trick controllers into trusting malicious routers. This access is considered ideal for nation-state actors seeking persistent, stealthy presence within networks to observe and influence operations over time. The response involves coordination with Five Eyes intelligence allies, highlighting the severe threat posed by advanced actors targeting critical networking infrastructure.
The Record from Recorded Future NewsCisco Patches Actively Exploited SD-WAN Zero-Day Vulnerability CVE-2026-20182
Cisco has released a patch for CVE-2026-20182, a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller and Manager that is being actively exploited as a zero-day. The flaw, located in the peering authentication mechanism of the vdaemon service, allows unauthenticated remote attackers to gain high-privileged access and reconfigure the SD-WAN fabric. Rapid7 researchers Jonah Burgess and Stephen Fewer discovered the issue while investigating a previous vulnerability, CVE-2026-20127. Cisco attributes the exploitation to a sophisticated threat group dubbed UAT-8616, whose infrastructure overlaps with Operational Relay Box (ORB) networks often linked to China-nexus espionage activities. Attackers have been observed escalating privileges to root by downgrading software versions to exploit older vulnerabilities before restoring the original version. Cisco advises customers to upgrade to fixed software releases immediately and monitor logs for unauthorized SSH key additions to the vmanage-admin account. While exploitation appears limited so far, the company urges vigilance and offers technical assistance for investigation. Additional fixes were issued for non-exploited information disclosure and privilege escalation flaws in the same product line.
Help Net SecurityCisco Issues Emergency Patches for Actively Exploited SD-WAN Zero-Day Vulnerability
Cisco has released emergency patches for a critical zero-day vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager components. The flaw, rated with a maximum severity score of 10.0, allows unauthenticated remote attackers to bypass authentication and gain administrative privileges. Once inside, attackers can issue arbitrary NETCONF commands to steal data, intercept traffic, manipulate firewall rules, or disrupt network operations. Cisco confirmed that the vulnerability was actively exploited in May 2026, though no specific threat actors have been attributed. In response, the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog and issued a rare three-day deadline for Federal Civilian Executive Branch agencies to apply fixes. Researchers at Rapid7 identified the issue, noting that the bug stems from a failure in the peering authentication mechanism. Cisco stated that no workarounds exist and urged administrators to immediately patch systems and audit authentication logs for signs of compromise, such as unexpected public key acceptances. This incident highlights ongoing security challenges for enterprise network infrastructure.
www.theregister.com - ArticlesCisco Issues Emergency Patches for Actively Exploited SD-WAN Zero-Day Vulnerability
Cisco has released emergency patches for a critical zero-day vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager components. Assigned a maximum severity score of 10.0, the flaw allows unauthenticated remote attackers to bypass authentication and gain administrative privileges. This access enables the execution of arbitrary NETCONF commands, potentially leading to data theft, traffic interception, firewall manipulation, or network disruption. Cisco confirmed that the vulnerability is being actively exploited in the wild, although no specific threat actors have been attributed. In response, the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog and issued a rare three-day deadline for Federal Civilian Executive Branch agencies to apply fixes. Researchers at Rapid7 identified the issue, noting that the bug stems from a failure in the peering authentication mechanism. Cisco stated that no workarounds are available and strongly urges all administrators to patch immediately. Affected organizations are advised to audit authentication logs for indicators of compromise, specifically looking for suspicious entries in the auth.log file related to the vmanage-admin account.
www.theregister.com - ArticlesCISA Adds Critical Cisco SD-WAN Vulnerability to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20182, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, to its Known Exploited Vulnerabilities (KEV) catalog. This action mandates Federal Civilian Executive Branch agencies to remediate the issue by May 17, 2026. The vulnerability, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to gain administrative privileges. Cisco attributes active exploitation with high confidence to threat cluster UAT-8616, which also weaponized related vulnerabilities. Post-compromise activities include adding SSH keys, modifying configurations, and escalating privileges. The infrastructure overlaps with Operational Relay Box networks, and at least ten different threat clusters are linked to exploiting these flaws since March 2026. Attackers leverage public proof-of-concept code to deploy various web shells, such as XenShell, Godzilla, and Behinder, enabling arbitrary command execution. Other malicious activities observed include cryptocurrency mining, credential stealing, and deploying backdoors. Cisco urges customers to follow advisory guidelines to secure their environments against these widespread and severe threats.
The Hacker News