HomeUpdatesCisco Catalyst SD-WAN Controller: Fix critical zero-day vulnerability

Cisco Catalyst SD-WAN Controller: Critical zero-day vulnerability fixed

Cisco is warning of a critical vulnerability in the Catalyst SD-WAN Controller that could be exploited in zero-day attacks, allowing attackers to gain administrative privileges on compromised systems. The vulnerability, listed as CVE-2026-20182, has a maximum severity rating of 10.0 and affects the Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager.

Cisco Catalyst SD-WAN Controller

According to the advisory published by Cisco, the issue arises from a peering authentication that “does not function properly.” An attacker can exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal user with elevated privileges. Using this account, the attacker could gain access to NETCONF, which would then allow them to manipulate the network configuration for the SD-WAN fabric.

The vulnerability affects the following deployments:

  • On-Prem Deployment
  • Cisco SD-WAN Cloud-Pro
  • Cisco SD-WAN Cloud (Cisco Managed)
  • Cisco SD-WAN for Government (FedRAMP)

Cisco Catalyst SD-WAN is a networking platform that connects branch offices, data centers, and cloud environments through a centrally managed system. It uses a controller to securely route traffic between locations over encrypted connections. The company says it identified threat actors exploiting the vulnerability in May, but did not share details about how it was exploited.

See also: Cisco fixes zero-day vulnerability in Catalyst SD-WAN

Cisco: Technical details and breach indicators

Cisco has shared indicators of compromise (IOCs) that alert administrators to check for unauthorized peering events in the SD-WAN Controller, which could indicate attempts to register malicious devices into the SD-WAN fabric. By adding a malicious peer, an attacker could introduce a malicious device into the SD-WAN.

Cisco Catalyst SD-WAN Controller: Critical zero-day vulnerability fixed

The vulnerability was discovered by Rapid7, which noted similarities to a previous vulnerability, CVE-2026-20127, which also allowed authentication bypass in the same component.

CVE -2026-20127 was used in zero-day attacks by a threat actor tracked as “ UAT-8616 .” This suggests a long-standing interest by attackers in exploiting Cisco ’s SD-WAN product line .

See also: Cisco SSM On-Prem: Critical vulnerability threatens enterprise networks

Countermeasures and security recommendations for Catalyst SD-WAN Controller

Cisco has released security updates to address the vulnerability and says there are no workarounds that fully mitigate the issue. The company also recommends restricting access to management and control SD-WAN interfaces to trusted internal networks or authorized IP addresses only , and reviewing authentication logs for suspicious connection activity.

Administrators should review /var/log/auth.log for entries showing “Accepted publickey for vmanage-admin” from unknown IP. They should also compare the IP in the logs to the configured System IP addresses listed in the Cisco Catalyst SD-WAN Manager web UI . If an unknown IP address is successfully identified, administrators should consider the device as compromised.

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

Cisco Catalyst SD-WAN Controller: Critical zero-day vulnerability fixed

Cisco also recommends reviewing SD-WAN Controller logs for unauthorized peering activity, as attackers may attempt to register malicious devices within the SD-WAN fabric . The company strongly recommends upgrading to a patched software release, as this is the only way to fully address CVE-2026-20182 .

CISA added the vulnerability to the KEV List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to the Known Exploitable Vulnerabilities (KEV) list, requiring federal FCEB agencies to fix the problem by May 17, 2026.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS