Knox CVE Database
/
CVE-2026-20182
Critical
10.0

CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Added to the CISA KEV catalog:
May 14, 2026

Overview

Cisco Catalyst SD-WAN Controller, Manager, and Validator contain a broken peering authentication mechanism in the control connection handshake that allows a remote, unauthenticated attacker to gain administrative access. Affected components span all deployment types, including on-premises, cloud-managed, and FedRAMP environments. Specific affected version strings are listed in the version table above; consult the vendor advisory in References for the complete fixed-release boundaries.

A successful attacker logs in as the high-privileged vmanage-admin account and gains NETCONF access, enabling direct manipulation of SD-WAN fabric configuration across the entire deployment.

Vulnerability details

Affected vendor
Cisco
Affected product
Catalyst SD-WAN
Weakness type (CWE)
CWE-287

CWE-287 (Improper Authentication) describes a failure to properly verify the identity of a peer before granting access. In the Catalyst SD-WAN control plane, the handshaking process that authenticates peering connections between the Controller, Manager, and Validator components does not correctly validate connecting peers. Because the authentication gate is broken rather than absent, a crafted request can satisfy the check without presenting legitimate credentials, bypassing the trust boundary the peering mechanism is intended to enforce.


An attacker with network access to the SD-WAN control plane components sends crafted requests that exploit the broken peering authentication check. The advisory notes that internet-exposed systems are directly at risk. A successful exploit results in the attacker being authenticated as the vmanage-admin account, a high-privileged internal user. From that position, the attacker gains NETCONF access and can manipulate SD-WAN fabric network configuration across the entire deployment, affecting routing, policy, and connectivity for all managed sites.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit /var/log/auth.log on each control component for entries matching 'Accepted publickey for vmanage-admin' where the source IP does not appear in the configured System IPs listed under WebUI > Devices > System IP.
  • Review SD-WAN control connection peering logs for vmanage peering-type connections originating from IP addresses outside the known peer list, particularly connections established at unexpected times with no corresponding provisioning event.

Remediation

Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (see References) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (see References). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Federal (FCEB) remediation due date
May 17, 2026

Additional hardening

  • Upgrade SD-WAN vBond Orchestrator and vSmart Controller to 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.15.4.4, 20.15.5.2, 20.18.2.2, or 26.1.1.1 as applicable; see References for the full fixed-release table covering all affected products.
  • Before upgrading, run the 'request admin-tech' command on each control component to preserve forensic state; if auth.log shows unauthorized vmanage-admin logins, a software update alone is insufficient and Cisco TAC engagement is required.
  • Restrict network access to SD-WAN control plane components (Controller, Manager, Validator) to known peer IP addresses using perimeter ACLs or firewall policy, eliminating internet exposure of the peering interface.
  • Follow CISA Emergency Directive 26-03 and the associated Hunt and Hardening Guidance for Cisco SD-WAN Devices, both linked in References, for additional triage and exposure-reduction steps.

Key dates

Published (NVD)
May 14, 2026
Added to CISA KEV
May 14, 2026
Remediation deadline
May 17, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-20182 affect my FedRAMP authorization?

If Cisco Catalyst SD-WAN runs inside your authorization boundary, yes. CVE-2026-20182 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of May 17, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Remediate it immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-20182?

Knox does not patch your software. Remediating Cisco Catalyst SD-WAN is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with Knox's automated continuous monitoring platform and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-20182 surfaces, exposure appears during ongoing monitoring rather than only when an assessor flags it at review time, giving you the earliest possible window to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-20182's remediation deadline of May 17, 2026 has passed. What happens now?

If CVE-2026-20182 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item on your record. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.