Cisco SD-WAN Auth Bypass Still Active
Cisco Catalyst SD-WAN controllers face ongoing attacks from multiple clusters exploiting auth bypass flaws.
CVE-2026-20182 scores CVSS 10.0 via broken peering auth in vdaemon over DTLS port 12346. Attackers send crafted requests to impersonate peers, log in via NETCONF as vmanage-admin, and rewrite configs across the fabric. Zero-day for UAT-8616 since 2023, now actively exploited by 10 more groups post-PoC.
Hits Controller and Manager in on-prem, cloud, all versions before fixes like 20.9.9.1 or 20.12.7.1. CISA KEV mandates federal patches by May 17.
Attackers inject SSH keys and check control connections for challenge-ack:0.
