IOC Radar
TLP:WHITE1 IOC

CVE-2026-20182: Critical Authentication Bypass in Cisco SD-WAN Can Grant Admin Access

SP
SOC Prime
Published May 15, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREunknownCAPABILITYMetasploitVICTIMunknown
Adversary
Infrastructure
Capability(1)
Victim

Attack Flow6 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/6
Exploit Public-Facing Application
ActionBypass authentication
An unauthenticated remote attacker exploits CVE-2026-20182, an authentication bypass flaw in Cisco SD-WAN Controller.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise1

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2026-20182
exploitintel-blogmalware
High
59
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph1 total IOCs
CVE
CVE1Malware1REPORTCVE-2026-20182: Critical AMetasploit
scroll to zoom · drag to pan · click IOC to open