🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Cisco Catalyst SD-WAN Controller Auth Bypass Admin Access (CVE-2026-20182) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateMay 14, 2026
CVECVE-2026-20182
CVSS Score10.0
Affectedcatalyst_sd-wan_manager, sd-wan_vsmart_controller
📋Executive Summary
Cisco released patches for CVE-2026-20182, a maximum severity authentication bypass vulnerability in Catalyst SD-WAN Controller and SD-WAN Manager with a CVSS score of 10.0. The flaw affects peering authentication mechanisms and has been actively exploited in limited attacks to gain administrative access. Attackers can bypass authentication entirely and take full control of SD-WAN infrastructure.
⚠️Why It Matters for MSSPs
Your clients running Cisco SD-WAN are sitting ducks right now with admin access available to anyone who knows how to exploit this bypass. If you manage SD-WAN for clients and miss this patch window, you own the breach when it happens. This is not theoretical risk anymore.
Recommended Action
Contact every client running Cisco Catalyst SD-WAN Controller or SD-WAN Manager immediately and schedule emergency patching within 24 hours.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.