CVE-2026-20182 – Cisco Catalyst SD-WAN Manager
“When your network controller is exposed, attackers don’t knock—they take control.”
This patch addresses two Critical vulnerabilities in Cisco Catalyst SD-WAN Manager: CVE-2026-20182 and CVE-2026-20127. Both carry a CVSS score of 10.0, which is Critical severity. These issues allow attackers to gain unauthorized access and potentially execute actions that compromise the entire SD-WAN management plane. The update strengthens authentication and access controls to prevent unauthorized system-level interaction.
CVE-2026-20182 has a CVSS score of 10.0, which is Critical severity. CVE-2026-20127 has a CVSS score of 10.0, which is Critical severity. Active exploitation has been confirmed for both vulnerabilities, significantly increasing the risk to organizations using affected systems. A successful attack can lead to full control over network orchestration, impacting routing, segmentation, and overall enterprise connectivity.
Key Details
- Affected Product
- Cisco Catalyst Sd-wan Manager
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-287