Briefing

Cisco Vulnerabilities Prompt CISA Urgent Patch for Federal Agencies

security
by [email protected] (The Hacker News) · deadline 17 May 2027 · CVE-2026-20182

Remediate Cisco SD‑WAN Controller authentication bypass (CVE‑2026‑20182) by May 17 2026.

What to do now

Remediate Cisco SD‑WAN Controller by May 17 2026.

Summary

Cisco has identified two high‑severity security flaws that could allow attackers to gain administrative control over its networking and workload products. The first, CVE‑2026‑20223, affects the Secure Workload platform’s internal REST APIs, enabling unauthenticated users to read sensitive data and alter configuration settings across tenant boundaries. Cisco released patches for on‑premises versions 3.9, 3.10, 3.10.8.3, 4.0, and 4.0.3.17, and has already fixed the cloud‑based SaaS deployment. While the company reports no evidence of exploitation in the wild, it urges customers to upgrade to the latest fixed releases to protect zero‑trust microsegmentation environments from lateral movement.

The second flaw, CVE‑2026‑20182, is found in the Catalyst SD‑WAN product. Unlike the Secure Workload issue, this authentication bypass is actively exploited in the field. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE‑2026‑20182 to its Known Exploited Vulnerabilities (KEV) catalog and issued a directive requiring all federal agencies to apply the patch within three days. Cisco’s Product Security Incident Response Team (PSIRT) has confirmed that the vulnerability can grant full Site Admin privileges, allowing attackers to read confidential information and modify network configurations across multiple tenants.

Additional vulnerabilities have been reported in Crosswork Network Controller, where earlier denial‑of‑service flaws required manual reboot to remediate. These incidents underscore the growing attack surface of Cisco’s SD‑WAN and workload solutions, especially as organizations increasingly adopt zero‑trust architectures that rely on strict segmentation and least‑privilege access controls.

Federal agencies and enterprises that rely on Cisco’s networking stack must act swiftly. The CISA directive provides a narrow window for remediation, and Cisco recommends migrating to the latest patched releases as soon as possible. Failure to do so could expose critical infrastructure to unauthorized administrative access, data exfiltration, and service disruption.

The broader cybersecurity community views these incidents as a reminder that even well‑established vendors can harbor severe, exploitable flaws. Continuous monitoring, timely patching, and rigorous access controls remain essential defenses against evolving threats.

Key changes

  • CVE‑2026‑20182 is a critical authentication bypass in Cisco SD‑WAN Controller
  • FCEB agencies must remediate by May 17 2026
  • KEV catalog inclusion signals active exploitation
  • Cisco issued a patch, but many run older firmware
  • Failure to patch exposes sensitive traffic

Affects

internal

Source angles · 2 perspectives

The Hacker News
Independent angle

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

Open
Bleeping Computer
Independent angle

Cisco Secure Workload flaw gives Site Admin privileges

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting