CVE-2026-20182

● KEV CRITICAL

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new...

Affects 2 products across 2 vendors.

BCS9.98
CVSS 3.110.0
EPSS90.3%
Percentile100th
PatchUnknown
KEV Added2026-05-14
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to bypass authentication and obtain administrative privileges, leading to potential manipulation of network configurations. Immediate action is required to mitigate the risk of exploitation.

BSID: BS-2026-GLOBAL-271382-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20182?
A critical vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to bypass authentication and obtain administrative privileges, leading to potential manipulation of network configurations. Immediate action is required to mitigate the risk of exploitation.
What is the CVSS score for CVE-2026-20182?
CVE-2026-20182 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 90.3%.
Is CVE-2026-20182 actively exploited?
Yes. CVE-2026-20182 is in the CISA KEV catalog (added 2026-05-14). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-20182?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW PSIRT: [email protected]
What systems are affected by CVE-2026-20182?
CVE-2026-20182 affects: Cisco, Cisco, Francisco Burzi.
What NERC-CIP standard applies to CVE-2026-20182?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to critical control systems, which can compromise the security and reliability of the power grid.
What IEC 62443 requirement maps to CVE-2026-20182?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability in the authentication mechanism, which is critical for maintaining the security of the control system and preventing unauthorized access.
Vulnerability Details
CVE IDCVE-2026-20182
BSIDBS-2026-GLOBAL-271382-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-05-14
Last Modified2026-06-16
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.  A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An unauthenticated, remote attacker can exploit the vulnerability by sending crafted requests to the affected system, bypassing the peering authentication mechanism and gaining administrative privileges. This can lead to unauthorized access to NETCONF, allowing the attacker to manipulate network configurations for the SD-WAN fabric.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Catalyst Sd-Wan Manager
Cisco Sd-Wan Vsmart Controller
Francisco Burzi —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 82 Days
CISA KEV● Active Exploitation Confirmed (added 2026-05-14)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict network segmentation and access controls to limit exposure to the affected systems. Monitor network traffic for unusual activity and apply the latest vendor patches immediately.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to critical control systems, which can compromise the security and reliability of the power grid.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability in the authentication mechanism, which is critical for maintaining the security of the control system and preventing unauthorized access.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash4c76926084160ee5df6157f8c246240e318bb0eff28ad5598b1f5b7b8f237d566721443062d5d3fa90999192dc1f83e6e014e74ec9a48b8135d01835ecc6c55d
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2008-0029 10.0 Cisco Application Velocity System (AVS) before 5.1.0 is installed with defaul... CVE-2014-0659 10.0 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N rout... CVE-2014-0648 10.0 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 ... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-20182 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →