CVE-2026-20182
About
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Rainforest analyst review
A follow-on flaw in Cisco Catalyst SD-WAN's control plane — affecting the Controller (vSmart), Manager (vManage), and Validator (vBond) — where the peering authentication that is supposed to verify control-connection handshakes does not work correctly. An unauthenticated remote attacker sends crafted requests and is admitted to the fabric as an internal, high-privileged (non-root) account. From that account the attacker reaches NETCONF and can rewrite the network configuration for the entire SD-WAN fabric.
SD-WAN controllers are the brain of a distributed network, orchestrating routing and policy across every branch and site, so administrative control there is control over the organization's connectivity — traffic steering, segmentation, and the trust relationships between locations. This advisory specifically addresses a new weakness found after an earlier February 2026 fix, which is a reminder that the control connection remains a scrutinized attack surface. Apply Cisco's updated fix promptly across all three components, use the Show Control Connections guidance in the advisory to inspect for unexpected peers, and keep the SD-WAN control plane on isolated management networks unreachable from untrusted sources.
References
Related CVEs
Frequently asked questions
What is CVE-2026-20182?
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking.
How severe is CVE-2026-20182?
CVE-2026-20182 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2026-20182 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2026-20182?
Public advisories list the following as affected: catalyst sd-wan manager, sd-wan vbond orchestrator, sd-wan vsmart controller. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2026-20182?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
