EXPOSURES › CVE-2026-20182
CVE-2026-20182
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco Catalyst SD-WAN Controller allows unauthenticated remote attackers to bypass authentication and gain administrative privileges.
This authentication bypass vulnerability enables remote attackers to escalate privileges without credentials, posing a severe risk to DIB organizations relying on Cisco SD-WAN for network control. The vulnerability is actively exploited in the wild and linked to ransomware campaigns, making it a critical compliance failure for FedRAMP vendors and hardware suppliers. Organizations must immediately patch affected systems and audit access controls to prevent unauthorized administrative access.
Shame score — Active exploitation in the wild combined with ransomware linkage and unauthenticated remote access to administrative privileges represents a severe, avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |