Risk events that matter to specialty insurance
AI-powered event intelligence with automated detection, classification, and transparent review status
MonitoringImpact: MediumAI Generated

Cisco Catalyst SD-WAN Controller Critical Authentication Bypass Flaw Exploited in Zero-Day Attacks – May 2026

Global — affects Cisco Catalyst SD-WAN Controller deployments worldwideFirst detected: 14 May 2026, 20:55Updated: 2d ago2 reports
Cyber
PropertyCyberCasualty & Liability
No analyst brief has been published for this event.
No ground report has been published for this event.

Impact Assessment Rationale

MEDIUM: Admin recalibration. The event has a plausible London Market pathway, but the current evidence does not support HIGH: no confirmed market-moving insured loss, vessel total loss, major closure, quantified claims estimate, reinsurance trigger, or broad pricing/capacity response is evidenced.

View assessment methodology →

Loading map...

Summary

Cisco has issued a warning regarding a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller, tracked as CVE-2026-20182, which has been actively exploited in zero-day attacks. The flaw enables attackers to gain administrative privileges on compromised devices. The exploitation of SD-WAN infrastructure poses significant risks to enterprise and critical infrastructure networks globally, as SD-WAN controllers are widely deployed across corporate and government environments.

This summary is AI-generated from linked source reports and may change as more information becomes available. See our correction policy for how to report errors.

Structured Intelligence

known

  • Cisco has officially warned of the vulnerability CVE-2026-20182 affecting Catalyst SD-WAN Controllers.
  • The flaw is classified as critical and involves an authentication bypass.
  • The vulnerability has been actively exploited in zero-day attacks.
  • Exploitation allows attackers to gain administrative privileges on compromised devices.

reported

  • The attacks appear to have targeted SD-WAN infrastructure broadly, with global implications.

uncertain

  • The identity or attribution of the threat actors exploiting the zero-day is not confirmed in the source.
  • The full scope and number of affected organisations is not disclosed.
  • Whether a patch or mitigation has been released is not confirmed from the source excerpt.

Key Entities

CiscoCisco Catalyst SD-WAN ControllerCVE-2026-20182CISA (Cybersecurity and Infrastructure Security Agency)Cisco SD-WANUnited States Federal Agencies
Event started: 14 May 2026

Sources

Trade Media

Timeline

Status Change29 May 2026, 05:30

Status changed to monitoring

Auto-transitioned: no updates for 6 hours

Status Change29 May 2026, 05:30

Lifecycle changed

active → monitoring

Status Change28 May 2026, 22:36

Status changed to active

remediation: existing active criteria met

Status Change28 May 2026, 22:36

Lifecycle changed

developing → active

De-escalation25 May 2026, 21:18

Impact changed

high → medium

Status Change18 May 2026, 10:54

Status changed to developing

Auto-promoted: multiple sources

Corroboration18 May 2026, 10:54

Corroborating source

The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered all federal agencies to apply a patch for an actively exploited vulnerability in Cisco SD-WAN systems by Sunday. The flaw allows an unauthenticated remote attacker to bypass authentication and gain administrative privileges on affected systems. Cisco released a patch on Thursday alongside an advisory disclosing the severity of the vulnerability. The directive signals active exploitation in the wild, raising concerns for critical infrastructure and enterprise network security.

Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could "allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system."

Source: The Record (Cyber) (Trade Media) · View source

Initial Detection14 May 2026, 20:55

Initial Detection

Cisco has issued a warning regarding a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller, tracked as CVE-2026-20182, which has been actively exploited in zero-day attacks. The flaw enables attackers to gain administrative privileges on compromised devices. The exploitation of SD-WAN infrastructure poses significant risks to enterprise and critical infrastructure networks globally, as SD-WAN controllers are widely deployed across corporate and government environments.

Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices.

Source: BleepingComputer (Trade Media) · View source