Skip to content
Active Exploitation of Critical Vulnerability in Cisco Catalyst SD

Active Exploitation of Critical Vulnerability in Cisco Catalyst SD

Csa.Sg May 15, 2026

Cisco has released security updates to address a critical vulnerability in Cisco Catalyst SD-WAN Controller. Users and administrators of affected products are advised to update to the latest versions immediately.

Cisco has released security updates to address a critical authentication bypass vulnerability (CVE-2026-20182) affecting Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10.0 out of 10.

Due to the peering authentication mechanism in the control connection handshake not functioning properly, an unauthenticated remote attacker could send crafted requests to bypass authentication and gain administrative privileges on the affected system, enabling the attacker to access NETCONF and manipulate network configuration for the entire SD-WAN fabric.

This vulnerability is being actively exploited in the wild.

This vulnerability affects Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, regardless of device configuration.

This vulnerability affects all deployment types, including:

Cisco SD-WAN Cloud-Pro

Cisco SD-WAN Cloud (Cisco Managed)

Cisco SD-WAN for Government (FedRAMP)

This vulnerability affects the following Cisco Catalyst SD-WAN versions:

All releases earlier than 20.9

Users and administrators of affected products are advised to update to the latest versions immediately.