Close Menu
    What's Hot

    Hegseth’s Message to Asian Partners: Do More to Get More

    Opinion | Sorry, Republicans, Trump Doesn’t Love You Back

    Season Pass – The New York Times

    Facebook X (Twitter) Instagram
    Trending
    • Hegseth’s Message to Asian Partners: Do More to Get More
    • Opinion | Sorry, Republicans, Trump Doesn’t Love You Back
    • Season Pass – The New York Times
    • How eCosmetics Turns Beauty Shopping Into a Live Auction Game
    • Tello Mobile Plan Review (2026): Low Cost, Reliable Service
    • Transfer rumors, news: Liverpool’s Jones an Inter Milan target
    • Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow
    • Across the Middle East, Muslims Mark Eid Amid War and Crisis
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

    adminBy adminMay 14, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMay 14, 2026Vulnerability / Network Security

    Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

    Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks.

    The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0.

    “A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system,” Cisco said.

    The networking equipment major said the flaw stems from a malfunction of the peering authentication mechanism, which an attacker could exploit by sending crafted requests to the affected system.

    Cybersecurity

    A successful exploit could permit the attacker to log in to the Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account, and then weaponize it to access NETCONF and manipulate network configuration for the SD-WAN fabric..

    The vulnerability impacts the following deployments –

    • On-Prem Deployment
    • Cisco SD-WAN Cloud-Pro
    • Cisco SD-WAN Cloud (Cisco Managed)
    • Cisco SD-WAN for Government (FedRAMP)

    According to Rapid7, which discovered CVE-2026-20182, the shortcoming has its echoes in CVE-2026-20127 (CVSS score: 10.0), another critical authentication bypass impacting the same component. The latter is said to have been exploited by a threat actor called UAT-8616 since at least 2023.

    “This new authentication bypass vulnerability affects the ‘vdaemon’ service over DTLS (UDP port 12346), which is the same service that was vulnerable to CVE-2026-20127,” Rapid7 researchers Jonah Burgess and Stephen Fewer said. “The new vulnerability is not a patch bypass of CVE-2026-20127. It is a different issue located in a similar part of the ‘vdaemon’ networking stack.”

    That said, the end result is the same: a remote unauthenticated attacker can abuse CVE-2026-20182 to become an authenticated peer of the target appliance and carry out privileged operations.

    Cybersecurity

    Cisco, in its advisory, noted that it became aware of “limited exploitation” of the flaw in May 2026, urging customers to apply the latest updates as soon as possible.

    The company also said Catalyst SD-WAN Controller systems that are accessible over the internet and that have ports exposed are at increased risk of compromise. It’s recommending customers to audit the “/var/log/auth.log” file for entries related to Accepted publickey for vmanage-admin from unknown or unauthorized IP addresses.

    Another indicator is the presence of suspicious peering events in the logs, including unauthorized peer connections that occur at unexpected times and originate from unrecognized IP addresses, or involve device types that are inconsistent with the environment’s architecture.

    access Actively Admin Auth Bypass Catalyst Cisco controller Exploited Gain SDWAN
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleYoung founders are reshaping leadership
    Next Article Microsoft’s Unreleased Cloud Controller Has Been Spotted In The Wild And It’s Teeny
    admin
    • Website

    Related Posts

    PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    May 30, 2026

    What Iran Stands to Gain From a Truce Deal With the United States

    May 29, 2026

    Hands-On With Gemini Spark: I Gave It Access to My Life and It Friend-Zoned My Boyfriend

    May 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Hegseth’s Message to Asian Partners: Do More to Get More

    Opinion | Sorry, Republicans, Trump Doesn’t Love You Back

    Season Pass – The New York Times

    How eCosmetics Turns Beauty Shopping Into a Live Auction Game

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by