IC Technology & Surveillance — 2026-05-15

CISA Issues Emergency Directive for Cisco SD-WAN Vulnerability Under Active Exploitation

BLUFBack-to-back maximum-severity authentication bypasses in the same vdaemon code path indicate an unresolved architectural flaw, and agencies behind on Emergency Directive 26-03 cannot credibly assess compromise without first completing the hunt actions skipped earlier this year.

Cisco disclosed CVE-2026-20182 on May 14, a CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Manager allowing an unauthenticated remote attacker to bypass the peering authentication mechanism over DTLS port 12346 and obtain administrative privileges. Cisco confirmed limited exploitation in May 2026 and credited Rapid7 researchers Jonah Burgess and Stephen Fewer with discovery. CISA added the CVE to its Known Exploited Vulnerabilities catalog on the same date, directing FCEB agencies to follow Emergency Directive ED 26-03 guidance requiring system inventory, forensic artifact collection, patching, and threat hunting. Cisco's advisory notes that internet-exposed deployments face elevated risk and directs customers to audit authentication logs for unauthorized access under the vmanage-admin account.

Analysis
CVE-2026-20182 represents the second CVSS 10.0 authentication bypass in Cisco's SD-WAN peering stack within months, and its shared attack surface with CVE-2026-20127 points to a persistent architectural weakness in the vdaemon service rather than a discrete coding error resolved by prior patches. Cisco's confirmation of limited May 2026 exploitation, combined with Rapid7's finding that the vulnerable DTLS port 12346 code region overlaps with the pathway UAT-8616 has exploited since at least 2023, suggests actors already familiar with the earlier vulnerability likely pivoted to this vector with minimal retooling. The compromise pathway grants administrative privileges under the vmanage-admin account, enabling an attacker to manipulate SD-WAN fabric configuration at scale across both on-premises and FedRAMP cloud deployments. For agencies carrying compliance debt from ED 26-03's February and March 2026 deadlines, this KEV addition compounds exposure directly: patching CVE-2026-20127 does not close this attack path, and the hunt and hardening actions mandated months ago remain prerequisite to any confident damage assessment now.
4 sources
  1. CISA Adds One Known Exploited Vulnerability to Catalog
  2. ED 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems - CISA
  3. Cisco Security Advisory: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
  4. Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE