Cisco Catalyst SD-WAN Controller authentication bypass exploited as a zero-day (CVE-2026-20182)
Cisco disclosed a maximum-severity authentication bypass in Catalyst SD-WAN Controller and Manager that was already being exploited by the UAT-8616 cluster to gain administrative access, prompting CISA to give federal agencies three days to patch.
- Victim
- Cisco Catalyst SD-WAN Controller and Manager