Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Public Sector Action Security Patch Release

Cisco SD-WAN CVE-2026-20182 Exploitation, Patching, and KEV Response

Updated 15.05.2026 08:28
Case score 63
Case score 63 Members 4 Latest activity 15.05.2026 08:28
Active exploitation KEV: CISA KEV Patch available CVSS: 10.0 Critical
Members 4 First seen 05.03.2026 14:15 Last seen 15.05.2026 08:28 Updated 15.05.2026 08:28

Overview

Active exploitation of **CVE-2026-20182** has put **Cisco Catalyst SD-WAN Controller** and **Cisco Catalyst SD-WAN Manager** at risk of unauthenticated high-privilege access and management-plane tampering. Cisco released fixes after detecting exploitation in May and said no workaround fully mitigates the flaw. The picture sits within a wider **Catalyst SD-WAN** exploitation pattern after Cisco had already confirmed March exploitation of **CVE-2026-20128** and **CVE-2026-20122**, with chaining behavior noted but campaign overlap left unconfirmed. **CISA** has since added **CVE-2026-20182** to the **Known Exploited Vulnerabilities** catalog and set a **May 17, 2026** federal remediation deadline.

Signals

11 derived
Impact signals
Exploitation
Exploitation Active exploitation CVSS 10.0 Critical
CVEs/products
CVE CVE CVE
Victims/regions
Victim region United States
Remediation
Urgency Immediate KEV CISA KEV Remediation Patch available
Status
Policy stage Enforced
Threat context
Actor UAT-8616

Malware context

4 families · 5 tools
Tools
AdaptixC2 gsocket KScan Sliver XMRig

Member happenings

4 related
Vulnerability Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)
Updated 14.05.2026 23:09 Lead Contribution 60
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**CVE-2026-20182** is an actively exploited **authentication bypass** in **Cisco Catalyst SD-WAN Controller** and **Cisco Catalyst SD-WAN Manager**, creating a path to **administrative privileges** and SD-WAN configuration tampering. Cisco said it detected exploitation in **May** and released **security updates** to fully remediate the issue. CISA added the flaw to the **Known Exploited Vulnerabilities Catalog**, setting a **May 17, 2026** patch deadline for federal agencies.

Exploitation Wave Cisco Catalyst SD-WAN active exploitation wave
Updated 05.03.2026 14:15 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**Cisco** confirmed **active exploitation** of **two recently patched Catalyst SD-WAN vulnerabilities**, creating immediate risk for exposed systems that have not been fully remediated. The affected flaws are **CVE-2026-20128** and **CVE-2026-20122**. Cisco said the attacks appear to involve **chaining with other flaws**, which can increase the chance of privilege escalation and deeper system compromise. The company also said it is **unclear whether the exploits are part of the same campaign** or separate operations.

Public Sector Action CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182
Updated 15.05.2026 08:28 Context
Policy Stage Enforced

**CISA** added **CVE-2026-20182** to the **KEV catalog** and ordered **Federal Civilian Executive Branch agencies** to remediate **Cisco Catalyst SD-WAN Controller** by **May 17, 2026**, turning the flaw into a federal remediation priority because it is tied to active abuse. The move puts a concrete deadline on federal response and raises urgency around affected **Cisco SD-WAN** environments. It also reinforces the operational significance of the vulnerability for government networks.

Security Patch Release Cisco security patch release for CVE-2026-20182
Updated 14.05.2026 20:45 Context
Exploitation Active Exploitation CVSS 10.0 Critical Urgency Immediate Patch Patch Available

Cisco released **updates** for **CVE-2026-20182**, a **maximum-severity authentication bypass** in **Catalyst SD-WAN Controller/Manager**, after the flaw was **exploited in limited attacks**. The patch applies to affected **on-prem**, **Cloud-Pro**, **Cloud (Managed)**, and **FedRAMP** deployments. Cisco urged customers to install the **latest updates** as soon as possible because **internet-exposed systems** face higher compromise risk.