CVE-2026-20182 is a CVSS 10.0 auth bypass in Cisco Catalyst SD-WAN. Remote attackers can gain admin access. Immediate patching is required per CISA.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| catalyst_sd-wan_manager | * | 20.9.9.1 | vulnerable |
| catalyst_sd-wan_manager | 20.10 | 20.12.5.4 | vulnerable |
| catalyst_sd-wan_manager | 20.12.6 | 20.12.6.2 | vulnerable |
| catalyst_sd-wan_manager | 20.13 | 20.15.4.4 | vulnerable |
| catalyst_sd-wan_manager | 20.15.5 | 20.15.5.2 | vulnerable |
| catalyst_sd-wan_manager | 20.16 | 20.18.2.2 | vulnerable |
| catalyst_sd-wan_manager | 26.1 | 26.1.1.1 | vulnerable |
| catalyst_sd-wan_manager | 20.12.7 | 20.12.7 | vulnerable |
| sd-wan_vbond_orchestrator | * | 20.9.9.1 | vulnerable |
| sd-wan_vbond_orchestrator | 20.10 | 20.12.5.4 | vulnerable |
| sd-wan_vbond_orchestrator | 20.12.6 | 20.12.6.2 | vulnerable |
| sd-wan_vbond_orchestrator | 20.13 | 20.15.4.4 | vulnerable |
| sd-wan_vbond_orchestrator | 20.15.5 | 20.15.5.2 | vulnerable |
| sd-wan_vbond_orchestrator | 20.16 | 20.18.2.2 | vulnerable |
| sd-wan_vbond_orchestrator | 26.1 | 26.1.1.1 | vulnerable |
| sd-wan_vbond_orchestrator | 20.12.7 | 20.12.7 | vulnerable |
| sd-wan_vsmart_controller | * | 20.9.9.1 | vulnerable |
| sd-wan_vsmart_controller | 20.10 | 20.12.5.4 | vulnerable |
| sd-wan_vsmart_controller | 20.12.6 | 20.12.6.2 | vulnerable |
| sd-wan_vsmart_controller | 20.13 | 20.15.4.4 | vulnerable |
| sd-wan_vsmart_controller | 20.15.5 | 20.15.5.2 | vulnerable |
| sd-wan_vsmart_controller | 20.16 | 20.18.2.2 | vulnerable |
| sd-wan_vsmart_controller | 26.1 | 26.1.1.1 | vulnerable |
| sd-wan_vsmart_controller | 20.12.7 | 20.12.7 | vulnerable |
Consult the Cisco Security Advisory (cisco-sa-sdwan-rpa2-v69WY2SW) to identify and install the software updates provided by Cisco for Catalyst SD-WAN Manager, Controller, and Validator components.
Ensure systems are migrated to fixed versions such as 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.15.4.4, 20.15.5.2, 20.18.2.2, or 26.1.1.1 and later, depending on your specific software release train.
Implement infrastructure access control lists (iACLs) to limit control connection traffic and NETCONF access to known, trusted IP addresses only, reducing the public exposure of the peering authentication mechanism.
Follow CISA’s Hunt & Hardening Guidance for Cisco SD-WAN. Regularly execute the 'show control connections' command to inspect for unauthorized peering and audit NETCONF logs for unexpected configuration changes.
Organizations should monitor for unusual control plane traffic and unauthorized peering attempts. Specifically, use the 'show control connections' command to identify unexpected or non-validated peer connections. Audit NETCONF logs for administrative actions performed by internal, non-root accounts that do not align with scheduled maintenance. Additionally, implement network signatures to detect crafted peering authentication requests and follow CISA’s Emergency Directive 26-03 for specific hunting instructions and indicators of compromise.
Experience superior visibility and a simpler approach to cyber risk management