LOWMalware
Global

Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

·Source: Cisco Talos

Updated:

Executive Summary

Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.

Analysis

Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.

Indicators of Compromise (1)

CVE (1)
CVE-2026-20182
Source Attribution

Originally published by Cisco Talos on May 14, 2026.

Related Threats