CVE-2026-20182
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Description
CVE-2026-20182 is a CRITICAL authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) with a maximum CVSS 3.1 score of 10.0. The flaw lives in the peering authentication handshake on the control connection: the validation logic does not correctly verify peer identity, so an unauthenticated remote attacker can send crafted requests over the network and log in as an internal, high-privileged, non-root account on the affected system. From that account the attacker reaches NETCONF and from there can manipulate the network configuration of the entire SD-WAN fabric — routing, security policies, and tenant segmentation. CISA added CVE-2026-20182 to the KEV catalog on May 14, 2026, with an aggressive three-day remediation deadline of May 17, 2026, and instructed federal agencies to follow CISA Emergency Directive 26-03 for hunt-and-hardening guidance. The EPSS score of 0.259 (96.33 percentile) and the supplemental May-2026 advisory (which followed an earlier February-2026 disclosure) reflect very high active exploitation pressure against Cisco SD-WAN fabrics.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| cisco | catalyst sd-wan manager | < 20.9.9.1; >= 20.10, < 20.12.5.4; >= 20.12.6, < 20.12.6.2; >= 20.13, < 20.15.4.4; >= 20.15.5, < 20.15.5.2; >= 20.16, < 20.18.2.2; >= 26.1, < 26.1.1.1; 20.12.7 |
| cisco | sd-wan vbond orchestrator | < 20.9.9.1; >= 20.10, < 20.12.5.4; >= 20.12.6, < 20.12.6.2; >= 20.13, < 20.15.4.4; >= 20.15.5, < 20.15.5.2; >= 20.16, < 20.18.2.2; >= 26.1, < 26.1.1.1; 20.12.7 |
| cisco | sd-wan vsmart controller | < 20.9.9.1; >= 20.10, < 20.12.5.4; >= 20.12.6, < 20.12.6.2; >= 20.13, < 20.15.4.4; >= 20.15.5, < 20.15.5.2; >= 20.16, < 20.18.2.2; >= 26.1, < 26.1.1.1; 20.12.7 |
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk(Not Applicable)
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20182(US Government Resource)
Weakness Type
CWE-287: Improper Authentication
CWE-287 covers the case where a product accepts an identity claim from a remote actor but fails to verify (or insufficiently verifies) that the claim is genuine. In CVE-2026-20182 the peering authentication mechanism on the Cisco Catalyst SD-WAN control connection — the trust handshake between an SD-WAN Manager and the SD-WAN Controller (vSmart) peers it federates with — does not enforce the checks that should bind a connecting peer to a verified identity. As a result an attacker who can reach the control connection port can present a crafted handshake and be granted the privileges of an internal, high-privileged service account on the controller, including NETCONF access for end-to-end fabric configuration.
Learn more: CWE-287 — Improper Authentication
Impact Analysis
CVE-2026-20182 carries the maximum CVSS 3.1 score of 10.0 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — exploitable remotely over the network with low complexity, no privileges, no user interaction, and Scope:Changed, which means a successful exploit affects resources beyond the directly vulnerable component. Confidentiality, Integrity, and Availability are all rated High. The operational consequence is severe because Cisco Catalyst SD-WAN Manager and SD-WAN Controller (vSmart) are the brain of the SD-WAN fabric: they distribute routing policy, security policy, and tenant segmentation to every WAN edge device in the deployment. An attacker who reaches the internal high-privileged service account through this flaw can use NETCONF to rewrite OMP routes, alter data-policy ACLs, exfiltrate or pivot through inter-site VPN segments, disable security services, and persist configuration changes across the fabric. For service providers and large enterprises running SD-WAN as the core WAN substrate, a successful exploit is effectively a takeover of the entire wide-area network. The Scope:Changed rating captures this: the compromise crosses the trust boundary between the management plane and every connected branch.
Exploit Maturity
Active Exploitation: CISA added CVE-2026-20182 to the KEV catalog on May 14, 2026, with a federal remediation deadline of May 17, 2026 — a three-day window that signals observed exploitation against production Cisco Catalyst SD-WAN deployments. CISA simultaneously issued Emergency Directive 26-03 and follow-up Hunt and Hardening Guidance, the strongest mitigation posture CISA can take short of mandatory disconnection. Vendor Advisory: Cisco's security advisory cisco-sa-sdwan-rpa2-v69WY2SW describes this issue as a new vulnerability in the control-connection handshake discovered and fixed after the February-2026 advisory and includes Show Control Connections guidance for system checks. Exploitation Probability: The EPSS score of 0.259 (96.33 percentile) places the CVE in the top 4 percent of CVEs by predicted exploitation likelihood. Practical risk: Cisco Catalyst SD-WAN is the foundation of wide-area connectivity for very large enterprises, government agencies, and service providers — a compromised controller yields cross-tenant and cross-site control with no follow-on exploitation needed, which is why the May-2026 deadline is exceptionally short.
Remediation
- Upgrade to a fixed Catalyst SD-WAN Manager / SD-WAN Controller (vSmart) release immediately. Apply the version from the Cisco fixed-release matrix in cisco-sa-sdwan-rpa2-v69WY2SW: 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.15.4.4, 20.15.5.2, 20.18.2.2, 26.1.1.1 or later (depending on your release train). Upgrade SD-WAN Manager and all vSmart Controllers; mixed-version fabrics remain exposed.
- Follow CISA Emergency Directive 26-03. Execute the steps in ED 26-03 and the supplemental Hunt and Hardening Guidance: assess exposure, apply Cisco's mitigations, and run the prescribed hunt steps to look for unauthorized control connections, configuration changes, and account artifacts.
- Audit control connections with Cisco's Show Control Connections guidance. Run the
show control connectionsandshow control connection-historycommands referenced in the advisory to enumerate every peer currently or recently authenticated to your SD-WAN Manager / Controllers, and investigate any peer that cannot be matched to a known device or branch. - Reduce control-plane network exposure. Restrict the SD-WAN control-plane network (ports used for vManage/vSmart peering) to known device IP ranges via management ACL or out-of-band management VRF; require strong, unique certificates for every device in the fabric; rotate any control-plane certificates or secrets that may have been exposed.
- Apply CWE-287 hardening principles to the fabric long-term. Enforce MFA on SD-WAN Manager admin logins, treat the SD-WAN Manager as a Tier-0 management asset (no shared accounts, full session logging shipped to a tamper-evident SIEM), and subscribe to Cisco PSIRT and CISA notifications so future Cisco-SD-WAN issues are remediated within hours, not days — given Cisco's 26-1 release cadence covers very large fabrics in production.
Technical Details
CVE-2026-20182 is a CWE-287 improper-authentication flaw in the peering-authentication mechanism of Cisco Catalyst SD-WAN Controller (vSmart) and Cisco Catalyst SD-WAN Manager (vManage), addressed in Cisco's May-2026 supplemental advisory after a related February-2026 disclosure. The vulnerable code runs during the control-connection handshake — the process by which an SD-WAN device proves its identity to the SD-WAN Manager or to a vSmart Controller before being granted membership in the fabric. The handshake's identity-verification step does not correctly bind the connecting peer to a verified credential, so a crafted handshake from an attacker-controlled host can be accepted as a legitimate fabric component. Once authenticated, the attacker is logged in as an internal, high-privileged, non-root service account; from there the account has NETCONF access, which Cisco SD-WAN uses as the canonical south-bound configuration interface for routing policies, data policies, security policies, and tenant segmentation across the fabric. The CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H captures the operational shape: fully unauthenticated, remotely reachable, scope-changed exploitation with maximum impact on the management plane. The fix in 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.15.4.4, 20.15.5.2, 20.18.2.2, and 26.1.1.1 corrects the handshake validation; CISA's Hunt and Hardening Guidance complements the patch with retrospective detection guidance because the underlying authentication weakness leaves no obvious access-log breadcrumb on exploitation.
Frequently Asked Questions
Is CVE-2026-20182 being actively exploited?
Yes. CISA added CVE-2026-20182 to the KEV catalog on May 14, 2026, with a three-day federal remediation deadline of May 17, 2026 and issued Emergency Directive 26-03 alongside the listing — both are strong signals that exploitation against deployed Cisco Catalyst SD-WAN fabrics has been observed. The EPSS score of 0.259 (96.33 percentile) reflects continued high exploitation likelihood.
What products are affected by CVE-2026-20182?
Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) and Cisco Catalyst SD-WAN Controller / vSmart Controller are affected across many release trains, including all releases earlier than 20.9.9.1, the 20.10–20.12.5.4 range, 20.12.6 up to 20.12.6.2, 20.13–20.15.4.4, 20.15.5–20.15.5.2, 20.16–20.18.2.2, 26.1 up to 26.1.1.1, and the specific release 20.12.7. Refer to the Cisco advisory for the authoritative fixed-release matrix.
How do I fix CVE-2026-20182?
Upgrade to the fixed release for your train as listed in the Cisco advisory, execute CISA Emergency Directive 26-03 and the supplemental Hunt and Hardening Guidance, audit show control connections for unrecognized peers, restrict control-plane network exposure via management ACL or out-of-band VRF, and rotate any control-plane certificates that may have been exposed.
How severe is CVE-2026-20182?
CVE-2026-20182 is rated CRITICAL with the maximum CVSS 3.1 score of 10.0 — unauthenticated, network-reachable, low-complexity, scope-changed, with full High impact on Confidentiality, Integrity, and Availability. Combined with KEV listing, CISA Emergency Directive 26-03, the three-day remediation deadline, and the 96.33-percentile EPSS score, CVE-2026-20182 is one of the most urgent network-infrastructure CVEs of 2026.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.