Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
2026-05-14T19:24:11Z•dd0a52d45d70af56c5a86a4aab748391793e283e40a2d65e1c5363bf6b5b70d7
active-exploitationauth-bypassciscodead.lettereximfragnesiagemstufferghostwriterheap-overflowlinux-kernellpemini-shai-huludnginxnode-ipcnode-ipc-malicenpmpraisonaircerubygemssupply-chaintrickmowindows-zero-day
What happened
Multiple high-severity and actively exploited vulnerabilities plus large supply-chain incidents were reported. Key technical highlights: Cisco Catalyst SD‑WAN Controller auth bypass (CVE-2026-20182, CVSS 10.0) is being actively exploited to gain admin access; Exim BDAT memory-corruption/possible RCE (CVE-2026-45185, “Dead.Letter”, CVSS 9.8); an 18‑year NGINX ngx_http_rewrite_module heap overflow enabling unauthenticated RCE (CVE-2026-42945, CVSS 9.2); Linux kernel local privilege escalation “Fragnesia” (CVE-2026-46300, CVSS 7.8); and PraisonAI missing-auth endpoints (CVE-2026-44338, CVSS 7.3)—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- dd0a52d45d70af56c5a86a4aab748391793e283e40a2d65e1c5363bf6b5b70d7
- Enrichment time
- 2026-05-14T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.