Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026
2026-05-15T07:24:03Z•e51f2e42a9bfd554fa5e2035671dbf6870910213c166179a26317c4cf7ba9a1c
CVE-2026-20182CVE-2026-46300UAT-8616ai-sbomakamaibig-ipbig-iqchinese-aptciscof5fragnesialayerxlinux-kernelnginxpraisonaiprivilege-escalationpwn2ownsalt-typhoonsd-wansupply-chaintwill-typhoonvmware-fusionzero-day
What happened
SecurityWeek roundup: Cisco patched an actively exploited SD‑WAN zero‑day (CVE-2026-20182) tied to threat actor UAT-8616. A new Linux kernel local privilege escalation dubbed “Fragnesia” (CVE-2026-46300) was disclosed, similar to Dirty Frag/Copy Fail. Other notable items include rapid exploitation attempts against a PraisonAI authentication bypass, Broadcom/VMware Fusion high‑severity fixes, F5 quarterly advisories covering 50+ flaws, expanding Chinese APT campaigns (Salt Typhoon, Twill Typhoon), and G7 guidance on AI SBOMs. Corporate moves and tooling notes: Akamai’s acquisition of LayerX and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- e51f2e42a9bfd554fa5e2035671dbf6870910213c166179a26317c4cf7ba9a1c
- Enrichment time
- 2026-05-15T07:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.