Cisco Security Updates – 15 May 2026

Cisco has released security updates to address several vulnerabilities affecting multiple Cisco products.

The addressed vulnerabilities could allow the attacker to obtain sensitive information, gain elevated privileges, bypass security restrictions, and gain access to the affected systems.

Sample of addressed vulnerabilities:

1. Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE- 2026-20182):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Security Bypass

2. Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability (CVE-2026-20224):

  • CVSS: 8.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

The affected products:

  • Cisco Catalyst SD-WAN Controller.
  • Cisco Catalyst SD-WAN Manager.

It should be highlighted that Cisco is aware that the vulnerability “CVE-2026- 20182” is being exploited in the wild.

Vulnerabilities
  • CVE-2026-20182
  • CVE-2026-20224
  • CVE-2026-20209
  • CVE-2026-20210
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Updates

References