The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via BleepingComputer

BleepingComputer · track record
76Stories
100%Verified
430d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
VERIFIEDBy Xavier Rivera· ·2.5 min read

Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days

Cisco disclosed that CVE-2026-20182, a critical authentication bypass in its Catalyst SD-WAN Controller and Manager, is being actively exploited in zero-day attacks allowing high-privileged access and network configuration manipulation. CISA has added the flaw to its Known Exploited Vulnerabilities Catalog with a patching deadline of May 17, 2026 for federal agencies while Cisco released updates but no full workarounds.

Source:BleepingComputer
Post
Cisco Warns of Critical SD-WAN Flaw Actively Exploited in Zero-Days
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Cisco warns of CVE-2026-20182, a critical 10.0-severity authentication bypass in Catalyst SD-WAN Controller and Manager for on-premises and cloud deployments, actively exploited in zero-days. Attackers gain high-privileged access to manipulate configurations via NETCONF and add rogue peers for network control. CISA adds it to Known Exploited Vulnerabilities Catalog, mandating federal patches by May 17, 2026.

Cisco has issued an advisory about a severe authentication bypass vulnerability, identified as CVE-2026-20182, that threat actors have leveraged in zero-day attacks to obtain administrative access on targeted systems.

The flaw carries the highest possible CVSS score of 10.0 and affects both the Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager across on-prem installations as well as SD-WAN Cloud environments. According to the company, the root cause lies in a peering authentication mechanism "that is not working properly." The advisory explains that an attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful compromise reportedly lets the intruder authenticate to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user. From there, the attacker could reach NETCONF functions and alter network settings across the SD-WAN fabric.

Cisco Catalyst SD-WAN functions as a software-defined platform designed to link branch offices, data centers, and cloud resources under centralized management, directing traffic between locations over encrypted tunnels.

The vendor reportedly identified exploitation attempts during May without disclosing specific attack techniques. Indicators of compromise direct administrators to scan SD-WAN Controller logs for signs of unauthorized peering events that might reflect efforts to onboard rogue devices into the fabric. Such rogue peers could enable insertion of attacker-controlled hardware that mimics legitimate nodes, allowing encrypted links and the advertisement of malicious networks to facilitate lateral movement.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Security researchers at Rapid7 uncovered the issue while investigating a separate Cisco SD-WAN controller vulnerability, tracked as CVE-2026-20127, which received a patch in February. That earlier flaw had also been exploited in zero-day operations by a group designated "UAT-8616" since 2023 for the purpose of establishing rogue peers inside victim environments.

Cisco has issued updated software releases that resolve CVE-2026-20182 and stated there are no workarounds capable of completely eliminating the risk. The vendor further advises limiting exposure of SD-WAN management and control-plane interfaces exclusively to trusted internal networks or approved IP ranges, along with routine inspection of authentication logs for anomalous activity.

CISA has placed the Cisco CVE-2026-20182 flaw on its Known Exploited Vulnerabilities Catalog, directing federal agencies to apply fixes no later than May 17, 2026.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Cisco additionally urges organizations with internet-facing Catalyst SD-WAN Controllers to examine logs for evidence of suspicious access or peering attempts, including entries in /var/log/auth.log that contain "Accepted publickey for vmanage-admin" originating from unfamiliar addresses. Any such IP should be cross-checked against authorized System IPs shown in the Cisco Catalyst SD-WAN Manager interface under WebUI > Devices > System IP; mismatched successful logins warrant treating the system as breached and contacting Cisco TAC.

EXPERT TAKE

Administrators should review /var/log/auth.log for "Accepted publickey for vmanage-admin" entries from unknown IPs not matching configured System IPs and restrict management interface access to trusted networks per Cisco's guidance.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CiscoSD-WANVulnerability
More fromBleepingComputer
  • OpenAI confirms GPT-6 Astra reaches Critical cybersecurity threshold

    Tech · 18d
  • Mathspace breach exposes data of 1,079,819 users

    Tech · 19d
  • OpenAI Begins Gradual Release of Astra to ChatGPT Plus Subscribers

    Tech · 20d
More inTech
  • This week in tech: Meta Connect, 2 nm chips at Xiaomi and Apple, plus new AI models

    Tech · 30m
  • OpenAI pauses model training after AI agents breach sandbox again

    Tech · 17h
  • CISA Adds WordPress Core Flaw CVE-2026-87902 to KEV Catalog

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    CISA Adds Cisco Email Gateway Flaw to KEV Catalog

    CISA added CVE-2026-76461, a SQL injection flaw in the Cisco email security appliance, to its Known Exploited Vulnerabilities catalog on 2026-09-14. Federal agencies have until 2026-09-17 to apply vendor mitigations under BOD 26-04, with forensic triage required.

  • Tech· 

    High-Severity Flaw in D-Link DIR-895L Router Has a Public Exploit

    CVE-2026-100740 is an out-of-bounds write in the L2TP code of the D-Link DIR-895L router on firmware A1_102b07. It can be triggered remotely, scores 8.6 (high), and an exploit is public.

  • Tech· 

    IBM Discloses Two More Guardium Data Protection 12.2 Flaws, Including a CVSS 8.8 Bug

    NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.

  • Tech· 

    Microsoft Outlook Flaw CVE-2026-100208 Could Allow Remote Code Execution

    Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.

  • Tech· 

    IBM Power Server Firmware Flaw CVE-2026-93306 Can Crash the ASMI Web Interface

    CVE-2026-93306, published by NVD on September 25, lets an unauthenticated attacker on the management network crash the ASMI web server in IBM server firmware with a malformed HTTPS request. IBM rates it 7.1 (High) and has released fixed firmware for Power11, Power10 and Power9 systems.