Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

2026-05-15T07:24:03Ze51f2e42a9bfd554fa5e2035671dbf6870910213c166179a26317c4cf7ba9a1c
CVE-2026-20182CVE-2026-46300UAT-8616ai-sbomakamaibig-ipbig-iqchinese-aptciscof5fragnesialayerxlinux-kernelnginxpraisonaiprivilege-escalationpwn2ownsalt-typhoonsd-wansupply-chaintwill-typhoonvmware-fusionzero-day

What happened

SecurityWeek roundup: Cisco patched an actively exploited SD‑WAN zero‑day (CVE-2026-20182) tied to threat actor UAT-8616. A new Linux kernel local privilege escalation dubbed “Fragnesia” (CVE-2026-46300) was disclosed, similar to Dirty Frag/Copy Fail. Other notable items include rapid exploitation attempts against a PraisonAI authentication bypass, Broadcom/VMware Fusion high‑severity fixes, F5 quarterly advisories covering 50+ flaws, expanding Chinese APT campaigns (Salt Typhoon, Twill Typhoon), and G7 guidance on AI SBOMs. Corporate moves and tooling notes: Akamai’s acquisition of LayerX and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
e51f2e42a9bfd554fa5e2035671dbf6870910213c166179a26317c4cf7ba9a1c
Enrichment time
2026-05-15T07:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 · Baitaphish