CVE-2026-20182 could allow an unauthenticated attacker to bypass authentication and gain administrative privileges
CVE-2026-20182 could allow an unauthenticated attacker to bypass authentication and gain administrative privileges
The following platforms are known to be affected:
Cisco Catalyst SD-WAN Controller
(Formerly SD-WAN vSmart)
(Formerly SD-WAN vManage)
Additional Detail on Affected Products
CVE-2026-20182 affects the following Catalyst SD-WAN deployment types:
The Cisco SD-WAN solution has been rebranded as Cisco Catalyst SD-WAN. In addition, from Cisco IOS XE SD-WAN Release 17.12.1a and Cisco Catalyst SD-WAN Release 20.12.1, the following component changes apply:
May 2026: New vulnerability CVE-2026-20182
In February 2026, Cisco released a security advisory to address critical vulnerability CVE-2026-20127 and the NHS England National CSOC released high-severity Cyber Alert CC-4748 in response.
In May 2026, Cisco released a security advisory to address a new vulnerability designated CVE-2026-20182, which is addressed in this alert. Although the vulnerabilities are very similar, the remediation actions are different and CVE-2026-20182 is only addressed in newer patches. Affected organisations must review the remediation actions below.
Cisco has released a security advisory to address a critical vulnerability in Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Catalyst SD-WAN Manager (formerly SD-WAN vManage). Cisco Catalyst SD-WAN is a software-defined wide area network solution that enables secure, scalable, and flexible connectivity across enterprise networks.
Exploitation of CVE-2026-20182
Cisco has stated it is aware of limited exploitation of CVE-2026-20182 in the wild, and security researchers have released detailed technical write-ups.
Edge devices like Cisco Catalyst SD-WAN are often internet-facing by design and are highly attractive targets to attackers, and there are an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.
Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance , including patching edge devices as soon as possible if a critical vulnerability is identified.
Cisco has released another security advisory to address the following vulnerabilities in Catalyst SD-WAN:
The above vulnerabilities are not currently exploited. However, all of the vulnerabilities listed above can be remediated in the patches for CVE-2026-20182.
Affected organisations must review Cisco security advisory cisco-sa-sdwan-rpa2-v69WY2SW and complete the remediation steps detailed below.
Strongly Recommended: Perform a Comprehensive Compromise Assessment
Organisations are strongly encouraged to follow the steps listed in the "Indicators of Compromise" section of Cisco's Advisory cisco-sa-sdwan-rpa2-v69WY2SW .
Note: Organisations are strongly encouraged to complete this step first; or collect all relevant artifacts, including a snapshot of the device and all logs, to support threat hunting after patching. Patching before conducting the compromise assessment or collecting relevant artifacts may delete critical evidence.
If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected] .
Required: Update to a Fixed Version
Organisations must update Catalyst SD-WAN Controller and Catalyst SD-WAN Manager to a fixed version. Applying the patch for CVE-2026-20182 also remediates the other vulnerabilities disclosed by Cisco and mentioned in this Cyber Alert.
Organisations are strongly encouraged to use the Cisco Software Checker tool to determine the latest available version for their deployment.
Note: Catalyst SD-WAN releases earlier than 20.9 are end-of-life. Organisations running an end-of-life version must migrate to a supported version and apply the patch to address CVE-2026-20182.
Strongly Recommended: Hardening Guidance for Cisco Catalyst SD-WAN
Organisations are strongly encouraged to follow Cisco's hardening guidance for Catalyst SD-WAN.
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only permissions to those of a high-privileged user. A successful exploit could allow the attacker to access or modify configuration settings within Cisco Catalyst SD-WAN Manager as a high-privileged user.
Last edited: 15 May 2026 10:50 am
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
