Metasploit Wrap Up 05/22/2026
PoC publicCisco Catalyst SD-WAN ControllerHUSTOJBelow is the opening; the full story is at Rapid7 Blog.
From Rapid7 Blog
Another week, another authentication bypass
Our humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for CVE-2026-20182, a vulnerability gracing the Cisco Catalyst SD-WAN Controller. The devices, whose purpose is to control a software-defined (SD) wide-area-network (WAN) was unfortunately missing an extra A for authentication. An oversight that Cisco has duly patched.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.