ZeroHour
The Recordpublished ()ingested

CISA orders all federal agencies to patch exploited bug in Cisco SD

criticalVulnerabilityimportance 60CVE-2026-20182

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20182
Authentication Bypass in Cisco Catalyst SD-WAN Control Components

CVE-2026-20182 is a critical authentication flaw (CWE-287) in the control-connection peering authentication of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond). Because the peering authentication mechanism does not work properly, an unauthenticated, remote attacker can send crafted requests during the control-connection handshake and log in to the controller as an internal, high-privileged, non-root user without valid credentials. With this access, the attacker can reach NETCONF and manipulate network configuration across the entire SD-WAN fabric. Any organization running these Catalyst SD-WAN control components is affected, and the flaw carries a CVSS 3.1 score of 10.0 and a 91.5% EPSS score. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-14, confirming exploitation in the wild, amid a series of exploited Cisco SD-WAN zero-days including a compromise at a communications service provider.

Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components to the fixed releases identified in Cisco's May 2026 advisory (version numbers are not provided in this data). Use the advisory's 'show control connections' guidance to inspect control-connection handshaking for anomalies and audit for unauthorized high-privileged non-root accounts and unexpected NETCONF sessions. Operators — especially federal agencies — should follow CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices, including restricting internet exposure of SD-WAN management interfaces until patched.

10.092% KEV
  • Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
  • Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
  • Cisco Catalyst SD-WAN Validator / vBond Orchestrator (formerly SD-WAN vBond)
largeon the order of tens of thousands of affected control-plane systems (controllers, managers, validators) across enterprise, service-provider, and government…
Full article506 words · extracted from therecord.media · click to collapse

Federal agencies have until Sunday to patch a new critical vulnerability in Cisco SD-WAN systems after the bug was discovered by incident responders in March. 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said CVE-2026-20182 is a critical vulnerability tied to a previous campaign that caused international alarm in February

Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.” 

The company said the bug carries the maximum 10 out of 10 severity score and that exploitation was observed this month.  

In its own notice, CISA said federal agencies should not only apply the patch released by Cisco but follow additional guidance that was released in an emergency directive in February. That directive ordered all agencies to identify all Cisco SD-WAN systems within their networks, collect logs, hunt for evidence of compromise and provide all of the information to CISA within days.

CISA did not respond to requests for comment about what the new deadlines are for information that needs to be sent to them. 

Incident responders from Rapid7 discovered the vulnerability while researching the previous bug, which was similar but located in a different part of the networking stack. Douglas McKee, director of vulnerability intelligence at Rapid7, said in a blog post that the vulnerability “behaves like a master key.” 

“An attacker can present themselves to the controller as a trusted network router and, if the system accepts that claim without properly validating it, they can obtain the highest level of administrative access,” he said. 

“That is the cybersecurity version of a Jedi mind trick. The controller is effectively told to trust something it has no business trusting, as if an attacker waves a hand and says, ‘these are not the droids you are looking for.’ And with CVE-2026-20182, the controller just nods and lets them pass.”

The emergency directive released by CISA in February was coordinated with cybersecurity agencies from the Five Eyes intelligence alliance. All of the agencies urgently warned at the time that “an advanced threat actor” was actively exploiting the flaws in Cisco networking equipment.

McKee noted in his blog post that like the bug from February, CVE-2026-20182 is “ideal” for nation-state actors looking to pre-position themselves on victim networks. 

“They are usually not looking for a smash and grab. They want persistence. They want access that blends in. They want to sit in the right place long enough to observe, influence, and pivot when the time is right,” McKee wrote. “An SD-WAN controller is a great place to do that, because it lives in the middle of trust relationships most organizations rarely question.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-orders-all-federal-agencies-to-patch-cisco-sd-wan-bug