SECURITYTHE REGISTER
Patch time for Cisco SD-WAN admins as vendor drops yet another make-me-admin zero-day
Cisco admins must patch a max-severity make-me-admin bug affecting Catalyst SD-WAN Controller and Manager, which allows unauthenticated remote attackers to gain admin privileges. The vulnerability, CVE-2026-20182, has been exploited as a zero-day and was added to the Known Exploited Vulnerabilities catalog. Cisco strongly recommends applying available fixes.
Mentioned