🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Cisco SD-WAN Controller Authentication Bypass Active Exploit (CVE-2026-20182) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateMay 15, 2026
CVECVE-2026-20182
CVSS Score10.0
Affectedcatalyst_sd-wan_manager, sd-wan_vsmart_controller
📋Executive Summary
Cisco patched CVE-2026-20182, an authentication bypass vulnerability in Catalyst SD-WAN Controller and SD-WAN Manager that allows attackers to completely bypass authentication mechanisms. A highly sophisticated threat actor actively exploited this zero-day in the wild before the patch release. The flaw affects both on-premises and cloud deployments of Cisco's SD-WAN infrastructure.
⚠️Why It Matters for MSSPs
Your RMM and remote access tools likely traverse client SD-WAN infrastructure, meaning compromised controllers could intercept your management traffic or redirect it to attacker-controlled endpoints. Every client running Cisco SD-WAN becomes a potential breach source that reflects back on your security posture, and unpatched controllers give attackers network-level access to client environments you are contractually obligated to protect.
Recommended Action
Audit all client Cisco SD-WAN deployments within 24 hours and coordinate emergency patching for CVE-2026-20182 on both Controller and Manager components.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.