NinjaVPN
Intel Brief · Security Intelligence for Infrastructure Professionals
Issue #003 — May 18, 2026 ninjavpn.co · Noosphere LLC
The Week in Security

A CVSS 10.0 vulnerability in Cisco Catalyst SD-WAN is the headline this week, and it deserves the severity designation. CVE-2026-20182 allows unauthenticated remote attackers to gain full administrative control of SD-WAN controllers — no credentials required, no prior access needed. CISA added it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of May 17. If that deadline has passed and your organization has not patched, the question is the same one raised by last week’s Palo Alto CVE-2026-0300: not whether the scanning is happening, but whether it already succeeded.

Palo Alto’s second vulnerability this week, CVE-2026-0265, is a distinct problem from last week’s RCE. This is an authentication bypass in PAN-OS’s Cloud Authentication Service — the component organizations use for enterprise identity federation. When CAS is enabled and this vulnerability is present, remote attackers can bypass authentication entirely. Organizations that patched CVE-2026-0300 last week and considered Palo Alto remediation complete need to revisit that assessment.

Against this backdrop, the post-quantum infrastructure picture continues to mature. Cloudflare and AWS have deployed hybrid ML-KEM support for TLS 1.3 in production environments using the NIST FIPS 203 standard. This removes the “wait for production-ready implementations” objection from migration planning conversations. The tooling is available; the January 2027 CNSA 2.0 deadline for new NSS acquisitions is not waiting for the threat environment to settle.

The CISA vulnerability bulletin for the week of May 4 (sb26-131) cataloged the full scope of actively exploited CVEs across federal systems. The pattern across two consecutive weeks is clear: Palo Alto firewalls, Cisco SD-WAN controllers, and Cisco ASA/FTD stacks account for the majority of active exploitation targeting federal network perimeter infrastructure. These are not niche or legacy products — they are the standard-issue tools of federal network architecture.

Palo Alto’s internal AI scanning program, Mythos, found 75 vulnerabilities in their own products using GPT-5.5-class models over a matter of weeks. The significance is not the self-reported success — it is that the same AI-accelerated discovery capability is available to adversaries. The exploit window between discovery and deployment is compressing. Last week’s Intel Brief cited Zscaler’s ThreatLabz report documenting AI reducing exploit timelines from weeks to hours; Mythos confirms that capability is now being applied directly to the most widely deployed federal perimeter devices.

Federal contractors managing network infrastructure should leave this week with two action items: verify patch status on all Cisco SD-WAN and Palo Alto PAN-OS deployments, and begin treating the January 2027 CNSA 2.0 deadline as a current project milestone rather than a future planning item. Patching classical vulnerabilities buys time — it is not a substitute for migration.

Editor’s Note

Two consecutive weeks of critical Palo Alto and Cisco vulnerabilities on the same infrastructure federal contractors use for remote access and perimeter security. The CVE count matters less than the pattern — these platforms are being actively targeted. Patch status verification is not optional this month.

Post-Quantum
Cloudflare and AWS Deploy Hybrid ML-KEM for TLS 1.3 in Production Using NIST FIPS 203
Major infrastructure providers now support ML-KEM-768 in production — federal contractors can begin compatibility testing against FIPS 203 implementations without waiting for tooling to mature.
infoq.com/news/2026/03/cloudflare-post-quantum-ipsec/
CNSA 2.0 Compliance Requirements Detailed: ML-KEM-1024 Required for NSS by 2026, Exclusive Adoption by 2030
NSA mandates ML-KEM-1024 support for VPN and network equipment on National Security Systems — contractors must align procurement and deployment timelines with these specific algorithm requirements now, not at the 2027 deadline.
qusecure.com/cnsa-2-0-pqc-requirements-timelines-federal-impact/
Breach & Threat
Cisco Catalyst SD-WAN Authentication Bypass CVE-2026-20182 Added to CISA KEV — Federal Patch Deadline May 17 CVSS 10.0
Unauthenticated remote attackers gain full administrative control of SD-WAN controllers with no credentials required — federal contractors running Catalyst SD-WAN must treat this as an emergency remediation, not a scheduled patch cycle item.
thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html
Palo Alto PAN-OS CVE-2026-0265: Authentication Bypass in Cloud Authentication Service Critical
When Cloud Authentication Service is enabled, remote attackers can bypass identity federation controls entirely — organizations that patched CVE-2026-0300 last week must separately assess CAS deployment status for this distinct vulnerability.
rapid7.com/blog/post/etr-cve-2026-0265-authentication-bypass-in-palo-alto-networks-pan-os/
Federal & Compliance
CISA Vulnerability Bulletin sb26-131: Weekly Tracking of Exploited CVEs Across Federal Systems
Two consecutive weeks of Palo Alto and Cisco perimeter device exploitation dominate the KEV catalog — federal contractors should use this bulletin as the authoritative prioritization reference for remediation sequencing.
cisa.gov/news-events/bulletins/sb26-131
Industry
Palo Alto Mythos AI Program Discovers 75 Vulnerabilities in Its Own Products Using GPT-5.5-Class Models
AI-accelerated vulnerability discovery is now operating at the same speed adversaries can exploit — the compress from weeks to hours documented by Zscaler’s ThreatLabz report is being confirmed in practice on federal perimeter hardware.
axios.com/2026/05/13/palo-alto-networks-mythos-gpt-cybersecurity