
Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
Cisco disclosed that CVE-2026-20182, a critical authentication bypass in its Catalyst SD-WAN Controller and Manager, is being actively exploited in zero-day attacks allowing high-privileged access and network configuration manipulation. CISA has added the flaw to its Known Exploited Vulnerabilities Catalog with a patching deadline of May 17, 2026 for federal agencies while Cisco released updates but no full workarounds.
