Cisco expands two critical SD-WAN advisories to more affected products

Cisco has updated its advisories for the critical vulnerabilities CVE-2026-20182 and CVE-2026-20127 affecting Cisco Catalyst SD-WAN products. The original advisories were published in May and February respectively, and have now been extended to include Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, as a vulnerable component. Successful exploitation could allow an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on affected systems. Exploitation has been observed in the wild, and Cisco strongly advises upgrading vulnerable systems.

What this means for your organisation

The significant point here is not that new vulnerabilities appeared, but that the list of affected components has grown. Organisations that did the work in February and May may in good faith have concluded they were unaffected, and now are. SD-WAN governs connectivity between offices and data centres, and administrative privileges there let an attacker reroute or intercept traffic across the entire network. Active exploitation makes this urgent.

Berigo recommends

  • Re-read the updated advisories even if you assessed the originals, and check specifically for SD-WAN Validator.
  • Upgrade affected components without waiting for the next maintenance window.
  • Establish a routine for catching supplier updates to existing advisories, not only newly published ones.
  • Review administrator accounts and configuration changes in the SD-WAN environment for signs of abuse.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch