The short version
- Two authentication bypasses rated CVSS 10.0 became known in Cisco Catalyst SD-WAN during 2026: CVE-2026-20127 on 25 February and CVE-2026-20182 on 14 May, both already exploited.
- The responsible US agency added them to its catalogue of known exploited vulnerabilities and issued an emergency directive for CVE-2026-20182 with a deadline of 17 May 2026 — three days.
- Cisco Talos describes the actors' method: entry through the bypass, then a deliberate software downgrade, privilege escalation via an older flaw, and finally a restore to the original version.
- For operators this is less a product question than an architectural one: how reachable is your control plane, and how fast can you actually patch it?
An SD-WAN promises to bring the operation of many sites onto one surface. That is exactly what makes the surface a target: it is the single point from which all sites can be changed at once. In 2026 that theoretical statement became practical several times.
What happened in 2026
On 25 February 2026 Cisco released fixes for CVE-2026-20127, an authentication bypass in Catalyst SD-WAN Controller and Manager rated at the maximum CVSS 10.0. A remote, unauthenticated attacker could obtain administrative privileges. The flaw was already being exploited at disclosure.
On 14 May 2026 CVE-2026-20182 followed, likewise an authentication bypass at CVSS 10.0. The responsible US agency added it to its known exploited vulnerabilities catalogue the same day and issued an emergency directive with a deadline of 17 May 2026. Three days.
| Identifier | Rating | Type | Known exploited since |
|---|---|---|---|
| CVE-2026-20127 | CVSS 10.0 | Authentication bypass | 25 February 2026 |
| CVE-2026-20182 | CVSS 10.0 | Authentication bypass | 14 May 2026 |
| CVE-2026-20133 | CVSS 7.5 | Information disclosure | 20 April 2026 |
| CVE-2026-20128 | CVSS 7.5 | Credential access | 20 April 2026 |
| CVE-2026-20122 | CVSS 5.4 | Arbitrary file overwrite | 20 April 2026 |
| CVE-2022-20775 | CVSS 7.8 | Privilege escalation | used as a follow-on step |
The method — and why it frustrates detection
Cisco Talos describes a pattern for the observed activity that says more about the actors' maturity than the severity score does. After entry through the bypass they perform a software downgrade, then exploit a flaw already fixed in 2022 (CVE-2022-20775) for root privileges, and afterwards restore the original software version.
The last step is the interesting one. It ensures that a later look at the version number shows nothing unusual: the system is running the build it ran before. Talos points to evidence that this activity goes back at least to 2023.
Four consequences for your own architecture
This is no argument against SD-WAN and none against a particular vendor — centralised control is the same construction with the same consequences at every supplier. The questions that follow are product-independent:
Reachability of the control plane
Who can reach the management surface at all? For the affected services Cisco explicitly recommends restricting them from untrusted remote hosts on the internet. That is the single most effective measure and in most networks a configuration question, not a project.
A patch path measured in days
A three-day deadline cannot be met with a quarterly maintenance window. The control plane needs a defined emergency path: who decides, who executes, how it rolls back — rehearsed before it is needed.
Separate access paths
Management access does not belong on the same network as the payload, nor behind the same credentials. A dedicated path with its own authentication bounds what a bypass reaches.
Assume compromise rather than rule it out
After an exploited flaw, installing the patch is not enough. Talos names concrete checks: unexpected peering events in the logs, unrecognised IP addresses, created or deleted user accounts, unaccounted SSH keys and cleared log files.
The second thread: trusting the device itself
A separate finding from the same year shows how deep the question reaches. In a Cisco security advisory dated 25 March 2026 the vendor describes CVE-2026-20104, a secure boot bypass in IOS XE on Catalyst 9200 and several rugged series. The score is 6.1, the classification nevertheless “high” — because the flaw defeats a load-bearing security function: the check that only signed software runs at boot.
In practice that means the assumption “the device boots what we installed” is an assumption, not a certainty. It holds as long as physical access and high privileges are controlled — which lands the question back on access paths and traceability.
The link to the reporting duty
For entities in scope of NIS2 this has an immediate consequence. A compromised SD-WAN controller is not a local event but one with reach into every attached site — and the 24-hour early warning demands exactly that statement of reach. Anyone who has not cleanly bounded and logged the control plane cannot make it. How we build that evidence is described in the article on NIS2 and segmentation and under network security.
Sources
Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.
- FAQ about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)opens in a new tab
Tenable · retrieved 2 August 2026
- Active exploitation of Cisco Catalyst SD-WAN by UAT-8616opens in a new tab
Cisco Talos · retrieved 2 August 2026
- Cisco IOS XE Software for Catalyst and Rugged Series Switches Secure Boot Bypass Vulnerabilityopens in a new tab
Cisco Security Advisory · 25 March 2026 · retrieved 2 August 2026

