Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

2026-05-15T01:24:10Z50398aa4844ea6ae55589cc0224a8ffd31b061d8c9cdc132520ff57e7c2aa1d1
active-exploitationandroid-malwareauthentication-bypassciscodead.lettereximghostwriterlinux-kernellocal-privilege-escalationmini-shai-huludnginxnode-ipcnpm supply chainphishingpraisonairemote-code-executionrubyGemssd-wansecurity-patchstealersupply-chaintrickmowindows-zero-day

What happened

The Hacker News roundup highlights multiple high-severity vulnerabilities and active exploitation across infrastructure, supply chain, and AI tooling. Notable items include an actively exploited maximum-severity authentication bypass in Cisco Catalyst SD‑WAN Controller (CVE-2026-20182, CVSS 10.0) used to gain admin access; immediate attempted exploitation of PraisonAI missing-auth endpoints (CVE-2026-44338); a Linux kernel local privilege escalation variant dubbed Fragnesia (CVE-2026-46300); an 18‑year‑old NGINX rewrite module heap overflow enabling unauthenticated RCE (CVE-2026-42945); and a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
50398aa4844ea6ae55589cc0224a8ffd31b061d8c9cdc132520ff57e7c2aa1d1
Enrichment time
2026-05-15T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.