CVE-2026-20182 - Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

项目:Cisco

产品:Catalyst SD-WAN

添加日期:2026-05-14到期日:2026-05-17最后更新:May 14, 2026

漏洞名称

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

描述

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

已知用于勒索软件活动吗?

Unknown

采集行动

Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

其他说明

CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems

https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW

https://nvd.nist.gov/vuln/detail/CVE-2026-20182

相关新闻文章

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessJune 25, 2026

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root accessJune 24, 2026

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawJune 16, 2026

Cisco fixes SD-WAN vManage flaw exploited in zero-day attacksJune 15, 2026

Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableJune 6, 2026

相关 CWE