Critical authentication bypass in Cisco Catalyst SD-WAN under active exploitation
Cisco has disclosed a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller and SD-WAN Manager, tracked as CVE-2026-20182 with a CVSS score of 10.0. The flaw allows an unauthenticated remote attacker to gain administrative access by sending crafted requests.
Successful exploitation may let attackers manipulate SD-WAN fabric configurations and establish persistent access. The vulnerability affects multiple Catalyst SD-WAN releases across both on-premises and cloud-hosted deployments. Cisco has released software updates and no workarounds are available. Active exploitation has been observed, and Cisco advises immediate patching, investigation for indicators of compromise, and hardening of exposed SD-WAN infrastructure. Cisco has published indicators of compromise.
What this means for your organisation
The SD-WAN controller governs how traffic between all sites is routed. Whoever takes it over effectively takes over the network, and can alter traffic flow without touching a single server. With no workarounds available, patching is the only measure, and with exploitation already under way you must also hunt for traces. For multi-site organisations this belongs on the management agenda the same day.
Berigo recommends
- Install Cisco's update immediately, including in cloud-hosted deployments.
- Search for Cisco's published indicators of compromise to establish whether you are already affected.
- Check whether management interfaces are reachable from the internet, and restrict access to defined management networks.
- Review who holds administrative access to the SD-WAN solution, and remove unused accounts.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch