CISA Issues Emergency Directive for Cisco SD-WAN Vulnerability Under Active Exploitation
Cisco disclosed CVE-2026-20182 on May 14, a CVSS 10.0 authentication bypass in
CVE-2026-20182 represents the second CVSS 10.0 authentication bypass in Cisco's SD-WAN peering stack within months, and its shared attack surface with CVE-2026-20127 points to a persistent architectural weakness in the vdaemon service rather than a discrete coding error resolved by prior patches. Cisco's confirmation of limited May 2026 exploitation, combined with Rapid7's finding that the vulnerable DTLS port 12346 code region overlaps with the pathway UAT-8616 has exploited since at least 2023, suggests actors already familiar with the earlier vulnerability likely pivoted to this vector with minimal retooling. The compromise pathway grants administrative privileges under the vmanage-admin account, enabling an attacker to manipulate SD-WAN fabric configuration at scale across both on-premises and FedRAMP cloud deployments. For agencies carrying compliance debt from ED 26-03's February and March 2026 deadlines, this KEV addition compounds exposure directly: patching CVE-2026-20127 does not close this attack path, and the hunt and hardening actions mandated months ago remain prerequisite to any confident damage assessment now.
4 sources
- CISA Adds One Known Exploited Vulnerability to Catalog
- ED 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems -
CISA - Cisco Security Advisory: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
- Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access -
The Hacker News