As of 2026-07-28, CVE-2026-20182 has substantial public exploitation evidence: listed in CISA KEV, listed in ENISA EUVD (exploited) and a proof of concept. Most recent observation: 2026-05-23.
Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.
| Observation | Source | Date | |
|---|---|---|---|
| Public proof-of-concept | GitHub PoC | 2026-05-23 | View → |
| Listed in ENISA EUVD (exploited) | ENISA EUVD (Exploited) | 2026-05-14 | View → |
| Listed in CISA KEV | CISA KEV | 2026-05-14 | View → |
This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:
No ATT&CK technique mapped.
The MITRE CWE weakness type classified for this exposure class:
| Remediation due date | 2026-05-17 |
|---|---|
| Required action | Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. |
| Known ransomware campaign use | None recorded |
ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.
Get the assessment →Public evidence is not the whole picture. Limited or absent observed evidence is not the same as safety.
Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.
Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-07-28