Cisco SD-WAN CVE-2026-20182 Exploitation, Patching, and KEV Response
Case score 63
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 63
- Main story score
- 60
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 2
- Vulnerability Primary exploited vulnerability and management-plane risk anchor. main
- Security Patch Release Vendor remediation scope and the no-workaround conclusion for CVE-2026-20182. context
- Public Sector Action KEV listing, federal deadline, and urgency around remediation. context
- Exploitation Wave Earlier confirmed exploitation of other Catalyst SD-WAN flaws adds direct exploitation context and chaining risk on related management components. contributes
Overview
Latest development Open development history Cisco warns on CVE-2026-20182 and response actions Cisco warned that CVE-2026-20182 is a critical authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager that was being actively exploited in zero-day attacks and could grant administrative privileges, access NETCONF, and allow manipulation of SD-WAN network configuration. Cisco said security updates are available and that upgrading to a fixed software release is the only full remediation, while CISA added the flaw to the Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch affected devices by May 17, 2026.
-
Cisco attributes active exploitation to UAT-8616
Cisco attributed active exploitation of CVE-2026-20182 with high confidence to UAT-8616, the same cluster linked to CVE-2026-20127, and said the actor attempted to add SSH keys, modify NETCONF configurations, and escalate to root privileges after compromise.
-
CISA adds CVE-2026-20182 to the KEV catalog
CISA added CVE-2026-20182, a critical authentication bypass in Cisco Catalyst SD-WAN Controller and Manager that can let a remote unauthenticated attacker obtain administrative privileges, to the KEV catalog and required Federal Civilian Executive Branch agencies to remediate the vulnerability by May 17, 2026.
-
Cisco confirms active exploitation of two Catalyst SD-WAN vulnerabilities
Cisco updated its advisory to say it had become aware of active exploitation of CVE-2026-20128 in the Data Collection Agent (DCA) feature of Catalyst SD-WAN Manager and CVE-2026-20122 in the manager API. Cisco said the attacks appear to have been chained with other flaws, but it did not share attack details.