Cisco Catalyst SD-WAN Controller authentication bypass exploited as a zero-day (CVE-2026-20182)
Cisco disclosed a maximum-severity authentication bypass in Catalyst SD-WAN Controller and Manager that was already being exploited by the UAT-8616 cluster to gain administrative access, prompting CISA to give federal agencies three days to patch.
- Victim
- Cisco Catalyst SD-WAN Controller and Manager
On 14 May 2026, Cisco disclosed CVE-2026-20182, a CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Catalyst SD-WAN Manager (formerly vSmart and vManage), and confirmed it had already been exploited as a zero-day. The same day, CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 17 May, just three days, to remediate.
The vulnerability
The flaw lies in the peering authentication mechanism used when SD-WAN components establish control connections. By sending crafted requests, an unauthenticated remote attacker can bypass authentication and obtain administrative privileges on the controller. From there, an attacker can issue arbitrary NETCONF commands to change configuration, intercept traffic, alter firewall rules or take networks down. All deployment types are affected, including on-premises, Cloud-Pro, Cisco-managed cloud and FedRAMP environments, regardless of configuration. Cisco released patches for every supported release and said there are no workarounds. The bug was found by Rapid7 researchers Stephen Fewer and Jonah Burgess.
Exploitation
Cisco attributed the exploitation with high confidence to UAT-8616, the same threat cluster behind the exploitation of the earlier SD-WAN flaw CVE-2026-20127 in February 2026. After gaining access, the attackers tried to add SSH keys, modify NETCONF configurations and escalate to root. Researchers also tracked at least ten distinct clusters exploiting related SD-WAN flaws since March 2026 to drop web shells and command-and-control frameworks such as Godzilla, Behinder and Sliver.
Why it matters
SD-WAN controllers sit at the heart of enterprise and government wide-area networks, so administrative access to one gives an attacker leverage over every connected branch. CVE-2026-20182 was one in a long series of Cisco SD-WAN zero-days exploited during 2026, showing that network management planes have become a favored target for persistent intrusion.
Timeline
Cisco discloses CVE-2026-20182 with confirmed in-the-wild exploitation; CISA adds it to the Known Exploited Vulnerabilities catalog.
Deadline set by CISA for U.S. federal civilian agencies to remediate the flaw.
Sources
- thehackernews.comhttps://thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html
- theregister.comhttps://www.theregister.com/patches/2026/05/15/cisco-discloses-yet-another-sd-wan-make-me-admin-0-day/5241071
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/
- tenable.comhttps://www.tenable.com/blog/faq-about-the-continued-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities-uat-8616