CVE-2026-20182: CVSS 10.0 Cisco SD-WAN Authentication Bypass — 11 Threat Actor Clusters Are Inside Enterprise Networks Right Now
CVE-2026-20182 is a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller and Manager. No credentials. No complexity. No user interaction. An attacker sends four crafted DTLS packets, becomes a trusted control-plane peer, and gains full administrative access to enterprise network infrastructure. Actively exploited by UAT-8616 and 10 additional threat clusters. CISA Emergency Directive 26-03 mandates federal agency remediation by May 17. Patch now.
