Cisco has disclosed a maximum-severity (CVSS 10.0) authentication bypass vulnerability (CVE-2026-20182) in its Catalyst SD-WAN Controller and SD-WAN Manager platforms. The flaw allows unauthenticated remote attackers to bypass authentication, establish themselves as trusted peers, and gain administrative privileges, including access to NETCONF for manipulating network configurations. Cisco confirmed limited active exploitation in May 2026 and has released software fixes for versions 20.9 through 26.1.1. No workarounds exist, and organizations are urged to patch immediately. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, with federal agencies given until May 17th to remediate. The vulnerability was discovered by researchers at Rapid7.

3m read timeFrom csoonline.com
Post cover image