Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

2026-05-14T19:24:11Zdd0a52d45d70af56c5a86a4aab748391793e283e40a2d65e1c5363bf6b5b70d7
active-exploitationauth-bypassciscodead.lettereximfragnesiagemstufferghostwriterheap-overflowlinux-kernellpemini-shai-huludnginxnode-ipcnode-ipc-malicenpmpraisonaircerubygemssupply-chaintrickmowindows-zero-day

What happened

Multiple high-severity and actively exploited vulnerabilities plus large supply-chain incidents were reported. Key technical highlights: Cisco Catalyst SD‑WAN Controller auth bypass (CVE-2026-20182, CVSS 10.0) is being actively exploited to gain admin access; Exim BDAT memory-corruption/possible RCE (CVE-2026-45185, “Dead.Letter”, CVSS 9.8); an 18‑year NGINX ngx_http_rewrite_module heap overflow enabling unauthenticated RCE (CVE-2026-42945, CVSS 9.2); Linux kernel local privilege escalation “Fragnesia” (CVE-2026-46300, CVSS 7.8); and PraisonAI missing-auth endpoints (CVE-2026-44338, CVSS 7.3)—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
dd0a52d45d70af56c5a86a4aab748391793e283e40a2d65e1c5363bf6b5b70d7
Enrichment time
2026-05-14T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.