A maximum severity authentication bypass in Cisco's SD-WAN products lets attackers take full admin control with no valid credentials needed. This is actively exploited. CISA has listed it in the Known Exploited Vulnerabilities catalog. Immediate patching is required across all affected deployments.
- 🔴CVE-2026-20182 affects Cisco Catalyst SD-WAN Controller and SD-WAN Manager, both widely deployed in mid-market environments
- 🔓Attackers can bypass authentication entirely and take full control of SD-WAN infrastructure with no credentials required
- ⚡Active exploitation is confirmed with public proof of concept available. This is not theoretical risk.
- 🏢Clients using SD-WAN for multi-site operations or contractor access are at elevated risk. A compromised SD-WAN means a compromised network boundary.
- ⏱️Federal agencies have 72 hours to patch under CISA's KEV mandate. Your clients should treat that as their benchmark.
Immediately verify all Cisco SD-WAN instances across your client environments. Apply Cisco's published patches per CVE-2026-20182 guidance. If patching cannot happen within 48 hours, restrict management plane access to trusted IPs as a compensating control. Do not wait for your next scheduled patch cycle.
"A critical Cisco SD-WAN vulnerability is being actively exploited and requires your immediate attention. Attackers can gain full administrative access to your network without valid credentials. We are reviewing your environment now and will provide specific guidance within 24 hours. If you use Cisco SD-WAN products, please reach out to us directly today."
This is a starting point. Your team reviews and personalises before sending. Your name, your judgement, your client relationship.