← Blog
🛡️ Vulnerability8 July 2026

CVE-2026-20182: critical vulnerability in Cisco Catalyst SD-WAN, now in the CISA KEV catalog

Alert: CVE-2026-20182, a critical vulnerability (CVSS 10) in Cisco Catalyst SD-WAN, included in CISA KEV. What to do today.

OCIRIA security team

CVE-2026-20182: critical vulnerability in Cisco Catalyst SD-WAN, now in the CISA KEV catalog

In short

Cisco has published a critical vulnerability (CVE-2026-20182) affecting the controllers of its Catalyst SD-WAN networking platform [1]. The flaw allows a remote attacker, without needing credentials, to bypass authentication and gain administrative privileges over the affected system [1]. The vulnerability has a CVSS score of 10.0 out of 10, the maximum possible, and is rated critical by NVD [1]. It also appears in the Known Exploited Vulnerabilities (KEV) catalog maintained by the US agency CISA, indicating that active exploitation has already been observed in the real world [2]. If your company uses Cisco Catalyst SD-WAN Controller, SD-WAN Manager, or SD-WAN Validator, today's priority is to check the installed version and apply Cisco's patch as soon as possible.

What it is and why it matters

CVE-2026-20182 is a flaw in the peering authentication mechanism used by the components of Cisco Catalyst SD-WAN Controller (formerly known as SD-WAN vSmart), Cisco Catalyst SD-WAN Manager (formerly vManage), and Cisco Catalyst SD-WAN Validator (formerly vBond) [1]. According to the vendor's official description, the authentication mechanism between these elements does not work correctly, and an attacker can exploit this by sending crafted requests to the affected system [1]. If the attack succeeds, the attacker manages to log into the SD-WAN controller as an internal account with elevated privileges (though not root), and from there can access NETCONF, the management interface that allows modification of the network configuration across the entire SD-WAN infrastructure [1].

It matters because it combines several unusual risk signals together: on one hand, the CVSS score is the maximum, 10.0, reflecting a very high impact on the confidentiality, integrity, and availability of the affected system [1]; on the other, according to the vendor's own description the attacker does not need prior authentication to attempt it [1]; and, in addition, the vulnerability is already included in CISA's KEV catalog, which in practice means there is evidence of real exploitation, not just a theoretical risk [2]. SD-WAN is the network backbone of many organizations: it controls how sites, offices, and data centers connect to each other, so compromising the controller could give an attacker the ability to reconfigure traffic across an entire corporate network [1].

Who is affected

The vulnerability affects organizations using Cisco products from the Catalyst SD-WAN family: SD-WAN Controller, SD-WAN Manager, and SD-WAN Validator [1]. Cisco is the only vendor identified in this alert [1]. It is especially relevant for companies with distributed networks (multiple sites, stores, branch offices) that rely on SD-WAN to interconnect their locations, as well as for managed service providers that operate these controllers on behalf of clients.

How to know if you are vulnerable

We do not have here the exhaustive list of specific affected versions or which ones already include the patch, so the first step is to consult Cisco's official advisory for your exact version of SD-WAN Controller, SD-WAN Manager, or SD-WAN Validator. In parallel, it is worth reviewing which part of your network infrastructure is exposed to the internet or to untrusted networks: the fewer SD-WAN management services accessible from outside, the smaller the attack surface. At OCIRIA, our threat intelligence radar tracks this vulnerability based on data published in NVD and in the CISA KEV catalog [1][2], and can help you identify which assets in your exposed surface correspond to potentially affected Cisco technology.

How to protect yourself

1. Identify all the Cisco Catalyst SD-WAN Controller, SD-WAN Manager, and SD-WAN Validator instances you operate, along with their current version.

2. Consult Cisco's official advisory and apply the corresponding patch or update as soon as it is available for your version.

3. Restrict network access to the management interfaces of these controllers, allowing only connections from trusted administration networks.

4. Review logs and control connections for anomalous patterns, following the verification recommendations published by Cisco in its advisory.

5. Since the vulnerability is listed in CISA's KEV catalog [2], treat its remediation as a high priority within your patch management plan, ahead of other vulnerabilities without evidence of exploitation.

6. If you manage SD-WAN through a third-party provider, confirm with them that the patch has been applied and on what date.

Frequently asked questions

Do I need credentials to be affected? No. According to the vendor's official description, the attack can be carried out by a remote attacker without prior authentication [1].

Is this just a theoretical risk? No: the vulnerability is included in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating that confirmed active exploitation has occurred [2].

Does it affect vendors other than Cisco? Based on the available data, the only vendor identified in this alert is Cisco, in its products from the Catalyst SD-WAN family [1].

What priority should I give this compared to other vulnerabilities? High: it combines the maximum CVSS score (10.0) [1] with confirmed presence in KEV [2], two signals that justify treating it as urgent.

Sources

OCIRIA security team Threat monitoring & response · data from our real-time radar Live radar