CVE-2026-20182
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new...
Affects 2 products across 2 vendors.
Software does not prove or insufficiently proves that the user is who they claim to be.
Show all 10
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to bypass authentication and obtain administrative privileges, leading to potential manipulation of network configurations. Immediate action is required to mitigate the risk of exploitation.
BSID: BS-2026-GLOBAL-271382-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-20182?
What is the CVSS score for CVE-2026-20182?
Is CVE-2026-20182 actively exploited?
How do I remediate CVE-2026-20182?
What systems are affected by CVE-2026-20182?
What NERC-CIP standard applies to CVE-2026-20182?
What IEC 62443 requirement maps to CVE-2026-20182?
| CVE ID | CVE-2026-20182 |
|---|---|
| BSID | BS-2026-GLOBAL-271382-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-05-14 |
| Last Modified | 2026-06-16 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Source: NIST NVD / MITRE CVE Database
An unauthenticated, remote attacker can exploit the vulnerability by sending crafted requests to the affected system, bypassing the peering authentication mechanism and gaining administrative privileges. This can lead to unauthorized access to NETCONF, allowing the attacker to manipulate network configurations for the SD-WAN fabric.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | Catalyst Sd-Wan Manager | — |
| Cisco | Sd-Wan Vsmart Controller | — |
| Francisco Burzi | — | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2026-05-14) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict network segmentation and access controls to limit exposure to the affected systems. Monitor network traffic for unusual activity and apply the latest vendor patches immediately.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to critical control systems, which can compromise the security and reliability of the power grid.
This CVE maps to SR 7.6 because it involves a vulnerability in the authentication mechanism, which is critical for maintaining the security of the control system and preventing unauthorized access.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 4c76926084160ee5df6157f8c246240e318bb0eff28ad5598b1f5b7b8f237d566721443062d5d3fa90999192dc1f83e6e014e74ec9a48b8135d01835ecc6c55d |
This Vulnerability Is Being Actively Exploited
CVE-2026-20182 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →