You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-20182
About this tag
CVE-2026-20182 is a critical vulnerability in Cisco Catalyst SD-WAN Controller and Manager systems that allows an unauthenticated remote attacker to bypass authentication and gain administrative privileges. Cisco disclosed the flaw on May 14, 2026, and later confirmed limited exploitation. No workarounds are available; the only mitigation is upgrading to a fixed release. Administrators should audit controller logs for unauthorized access and restrict control-plane exposure. Any suspicious controller activity should be treated as a potential fabric-level incident. This tag covers discussions, updates, and guidance related to CVE-2026-20182, including patch deployment, exploitation reports, and security best practices for affected Cisco SD-WAN deployments.
Cisco warned on May 14, 2026, that CVE-2026-20182 can let an unauthenticated remote attacker bypass authentication and gain administrative privileges on affected Cisco Catalyst SD-WAN Controller and Manager systems, and Cisco later said its PSIRT had become aware of limited exploitation in May...