2026-05-15: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers episode artwork

EPISODE · May 15, 2026 · 29 MIN

2026-05-15: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers

from Cyber Threat Brief

Show Notes - 2026-05-15 Stories Covered: - Today: - Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182) (https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/) - Windows Zero-Day BitLocker Bypass (YellowKey) (https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html) - Microsoft Exchange Zero-Day (CVE-2026-42897) (https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/) - Foxconn North American Facilities Hit by Nitrogen Ransomware (https://www.darkreading.com/cyberattacks-data-breaches/foxconn-attack-manufacturing-cyber-crisis) - KongTuke Pivots to Microsoft Teams for Social Engineering (https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/) - Widespread Cisco SD-WAN Exploitation by Multiple Threat Clusters (https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/) - OpenAI Supply Chain Breach via TanStack Attack (https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/) - AI Application Misconfigurations Create Exploitable Attack Paths (https://www.microsoft.com/en-us/security/blog/2026/05/14/configuration-becomes-vulnerability-exploitable-misconfigurations-ai-apps/) - Windows Privilege Escalation Zero-Day (GreenPlasma) (https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html) - Federal Identity Security Critical in Age of AI (https://cyberscoop.com/white-house-federal-identity-security-ai-risks/) - Pwn2Own Berlin 2026 Day 1: $523,000 in Rewards for 24 Zero-Days (https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/) - Linux Kernel Privilege Escalation Vulnerability (Fragnesia - CVE-2026-46300) (https://www.securityweek.com/new-linux-kernel-vulnerability-fragnesia-allows-root-privilege-escalation/) - Secret Blizzard's Kazuar Evolves into Modular P2P Botnet (https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/) - Siemens Industrial Control Systems (Multiple Products) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10) - GnuTLS Authentication Bypass and Name Constraint Issues (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42011) - Twisted DNS Denial of Service (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42304) CVEs Referenced: CVE-2024-4367, CVE-2024-54017, CVE-2025-12659, CVE-2025-22871, CVE-2025-40833, CVE-2025-40949, CVE-2025-48804, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-25786, CVE-2026-25787, CVE-2026-25789, CVE-2026-27446, CVE-2026-33825, CVE-2026-33862, CVE-2026-33893, CVE-2026-40175, CVE-2026-41551, CVE-2026-42010, CVE-2026-42011, CVE-2026-42304, CVE-2026-42897, CVE-2026-44411, CVE-2026-44412, CVE-2026-46300 Full brief: https://carolinacleartech.com/brief/2026-05-15/

Episode metadata supplied by the publisher feed · Published May 15, 2026

Embed this episode

Show Notes - 2026-05-15 Stories Covered: - Today: - Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182) (https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/) - Windows Zero-Day BitLocker Bypass (YellowKey) (https:

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-05-15: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers

0:00 29:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 29 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on May 15, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!