BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Cisco SD-WAN Exploited Auth Bypass Patched

Cisco patches critical exploited SD-WAN flaw allowing full admin control.

  • Cisco patched a critical vulnerability (CVE-2026-20182) in its Catalyst SD-WAN software that has been exploited in limited attacks.
  • The flaw, with a maximum CVSS score of 10.0, allows unauthenticated remote attackers to bypass authentication and gain administrative privileges.
  • The vulnerability is similar to, but distinct from, a previously exploited issue (CVE-2026-20127) in the same ‘vdaemon’ service.
  • Systems exposed to the internet are at increased risk, and Cisco advises immediate patching and log review.

In May 2026, Cisco urgently addressed a critical security flaw in its widely used networking software after discovering it was already being exploited by attackers. The vulnerability, present in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, poses a severe threat to network integrity worldwide.

- Advertisement -

An attacker could exploit the malfunctioning peering authentication mechanism by sending crafted requests to a target system. Consequently, they could bypass all authentication and obtain full administrative control.

The issue was discovered by researchers at Rapid7, who detailed their findings in a public blog post. They noted the flaw’s technical echoes in a separate, previously exploited vulnerability tracked as CVE-2026-20127.

“This new authentication bypass vulnerability affects the ‘vdaemon’ service over DTLS (UDP port 12346), which is the same service that was vulnerable to CVE-2026-20127,” the researchers stated. However, they clarified that this is a different issue located in a similar part of the networking stack.

Successful exploitation grants attackers the ability to log in as a high-privileged user. They can then access sensitive interfaces to manipulate the configuration of the entire SD-WAN fabric.

- Advertisement -

The company’s official security advisory warned that internet-exposed systems are at the greatest risk. Consequently, Cisco is urging all impacted customers to apply updates immediately.

Organizations should audit their “/var/log/auth.log” file for unauthorized login attempts. Additionally, they must check for suspicious peering events from unrecognized IP addresses.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-Celsius Exec Sentenced to Time Served for Fraud

Roni Cohen-Pavon, former Celsius CRO, was sentenced to time served after pleading guilty to...

Sonic’s Vertical Integration Model Shows 400% Deflation Impact

Sonic's early Vertical Integration (VI) model generated $13,000 in product revenue over ten weeks,...

NVIDIA Surges Amid Trump-China Trip, H200 Deal Optimism

NVIDIA stock has surged 10% in five days, boosted by U.S. clearance for Chinese...

AI Agents Pursue Risky Goals, Ignore Safety

AI agents from leading firms like OpenAI and Anthropic exhibited dangerous or irrational behavior...

Warren Criticizes Crypto Industry-Backed Bill

Bitcoin's price rose above $81,000 as the Senate Banking Committee debated the CLARITY Act.Senator...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading