Skip to content
Zero-dayOngoing

Cisco Catalyst SD-WAN Controller authentication bypass exploited as a zero-day (CVE-2026-20182)

Cisco disclosed a maximum-severity authentication bypass in Catalyst SD-WAN Controller and Manager that was already being exploited by the UAT-8616 cluster to gain administrative access, prompting CISA to give federal agencies three days to patch.

Victim
Cisco Catalyst SD-WAN Controller and Manager
Threat actorUAT-8616
CVECVE-2026-20182

On 14 May 2026, Cisco disclosed CVE-2026-20182, a CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Catalyst SD-WAN Manager (formerly vSmart and vManage), and confirmed it had already been exploited as a zero-day. The same day, CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 17 May, just three days, to remediate.

The vulnerability

The flaw lies in the peering authentication mechanism used when SD-WAN components establish control connections. By sending crafted requests, an unauthenticated remote attacker can bypass authentication and obtain administrative privileges on the controller. From there, an attacker can issue arbitrary NETCONF commands to change configuration, intercept traffic, alter firewall rules or take networks down. All deployment types are affected, including on-premises, Cloud-Pro, Cisco-managed cloud and FedRAMP environments, regardless of configuration. Cisco released patches for every supported release and said there are no workarounds. The bug was found by Rapid7 researchers Stephen Fewer and Jonah Burgess.

Exploitation

Cisco attributed the exploitation with high confidence to UAT-8616, the same threat cluster behind the exploitation of the earlier SD-WAN flaw CVE-2026-20127 in February 2026. After gaining access, the attackers tried to add SSH keys, modify NETCONF configurations and escalate to root. Researchers also tracked at least ten distinct clusters exploiting related SD-WAN flaws since March 2026 to drop web shells and command-and-control frameworks such as Godzilla, Behinder and Sliver.

Why it matters

SD-WAN controllers sit at the heart of enterprise and government wide-area networks, so administrative access to one gives an attacker leverage over every connected branch. CVE-2026-20182 was one in a long series of Cisco SD-WAN zero-days exploited during 2026, showing that network management planes have become a favored target for persistent intrusion.

Timeline

  1. Cisco discloses CVE-2026-20182 with confirmed in-the-wild exploitation; CISA adds it to the Known Exploited Vulnerabilities catalog.

  2. Deadline set by CISA for U.S. federal civilian agencies to remediate the flaw.

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html
  2. theregister.comhttps://www.theregister.com/patches/2026/05/15/cisco-discloses-yet-another-sd-wan-make-me-admin-0-day/5241071
  3. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/
  4. tenable.comhttps://www.tenable.com/blog/faq-about-the-continued-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities-uat-8616

Related incidents

Zero-dayOngoing

SonicWall warns of two SMA 1000 zero-days exploited in the wild (CVE-2026-15409, CVE-2026-15410)

SonicWall issued an urgent advisory after attackers were caught chaining two zero-day flaws in its SMA 1000 secure remote-access appliances — an unauthenticated SSRF rated CVSS 10.0 and a post-authentication command-injection bug — with Rapid7 having observed the pair exploited in tandem against internet-facing devices before any patch existed.

Victim
SonicWall SMA 1000