Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A maximum-severity authentication bypass vulnerability (CVE-2026-20182) in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to seize full administrative control over an organization’s SD-WAN fabric. All deployment types are affected, including on-premises, cloud, and FedRAMP environments, with no available workarounds; patching is the only remediation path. Cisco has confirmed limited active exploitation, CISA has issued Emergency Directive ED-26-03, and a related SD-WAN zero-day (CVE-2026-20127) has been exploited by threat actor UAT-8616 since at least 2023, indicating a sustained, targeted campaign against this infrastructure.

Author

Tech Jacks Solutions