Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-20182

Published 2026-05-14
Updated 3 months ago
Vendor/s
Cisco
Product/s
Catalyst SD-WAN
Version/s
* > 20.9.9.1
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-20182 is a CVSS 10.0 auth bypass in Cisco Catalyst SD-WAN. Remote attackers can gain admin access. Immediate patching is required per CISA.

CPE

Cisco logo
Cisco
Product Version Start Version End (excl.) Status
catalyst_sd-wan_manager * 20.9.9.1 vulnerable
catalyst_sd-wan_manager 20.10 20.12.5.4 vulnerable
catalyst_sd-wan_manager 20.12.6 20.12.6.2 vulnerable
catalyst_sd-wan_manager 20.13 20.15.4.4 vulnerable
catalyst_sd-wan_manager 20.15.5 20.15.5.2 vulnerable
catalyst_sd-wan_manager 20.16 20.18.2.2 vulnerable
catalyst_sd-wan_manager 26.1 26.1.1.1 vulnerable
catalyst_sd-wan_manager 20.12.7 20.12.7 vulnerable
sd-wan_vbond_orchestrator * 20.9.9.1 vulnerable
sd-wan_vbond_orchestrator 20.10 20.12.5.4 vulnerable
sd-wan_vbond_orchestrator 20.12.6 20.12.6.2 vulnerable
sd-wan_vbond_orchestrator 20.13 20.15.4.4 vulnerable
sd-wan_vbond_orchestrator 20.15.5 20.15.5.2 vulnerable
sd-wan_vbond_orchestrator 20.16 20.18.2.2 vulnerable
sd-wan_vbond_orchestrator 26.1 26.1.1.1 vulnerable
sd-wan_vbond_orchestrator 20.12.7 20.12.7 vulnerable
sd-wan_vsmart_controller * 20.9.9.1 vulnerable
sd-wan_vsmart_controller 20.10 20.12.5.4 vulnerable
sd-wan_vsmart_controller 20.12.6 20.12.6.2 vulnerable
sd-wan_vsmart_controller 20.13 20.15.4.4 vulnerable
sd-wan_vsmart_controller 20.15.5 20.15.5.2 vulnerable
sd-wan_vsmart_controller 20.16 20.18.2.2 vulnerable
sd-wan_vsmart_controller 26.1 26.1.1.1 vulnerable
sd-wan_vsmart_controller 20.12.7 20.12.7 vulnerable

Related weakness (CWE)

CWE-287

Remediation plan

1

Apply official patches

Consult the Cisco Security Advisory (cisco-sa-sdwan-rpa2-v69WY2SW) to identify and install the software updates provided by Cisco for Catalyst SD-WAN Manager, Controller, and Validator components.

2

Update affected systems

Ensure systems are migrated to fixed versions such as 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.15.4.4, 20.15.5.2, 20.18.2.2, or 26.1.1.1 and later, depending on your specific software release train.

3

Restrict access

Implement infrastructure access control lists (iACLs) to limit control connection traffic and NETCONF access to known, trusted IP addresses only, reducing the public exposure of the peering authentication mechanism.

4

Monitor for exploitation

Follow CISA’s Hunt & Hardening Guidance for Cisco SD-WAN. Regularly execute the 'show control connections' command to inspect for unauthorized peering and audit NETCONF logs for unexpected configuration changes.

Detection Guidance

Organizations should monitor for unusual control plane traffic and unauthorized peering attempts. Specifically, use the 'show control connections' command to identify unexpected or non-validated peer connections. Audit NETCONF logs for administrative actions performed by internal, non-root accounts that do not align with scheduled maintenance. Additionally, implement network signatures to detect crafted peering authentication requests and follow CISA’s Emergency Directive 26-03 for specific hunting instructions and indicators of compromise.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management