LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 14, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 17, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities catalog on May 14, 2026, with a federal patch deadline of May 17, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges…

This vulnerability affects Cisco Catalyst SD-WAN Controller and Manager components. It allows an unauthenticated remote attacker to bypass authentication and gain administrative privileges on an affected system. Compromise of these systems can provide control over wide-area network infrastructure, making prompt assessment essential for organizations using the product.

How it works

The weakness is categorized as CWE-287, improper authentication. An attacker can exploit the flaw to circumvent normal login requirements on the affected controller or manager.

Successful abuse grants administrative access without valid credentials. Specific mechanics of the bypass must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Cisco Catalyst SD-WAN controllers and managers are typically deployed in enterprise network environments to manage software-defined wide area networks.

How to remediate

Apply the vendor update referenced in the official advisory as the primary remediation step.

After patching, review and strengthen authentication controls for SD-WAN management interfaces in line with general best practices for this class of vulnerability.

If you can't patch immediately

Follow CISA’s Emergency Directive 26-03 and Hunt & Hardening Guidance for Cisco SD-WAN Devices to assess and mitigate exposure.

Adhere to BOD 22-01 guidance for any cloud services involved, or discontinue use of the affected product if mitigations cannot be applied.

Additional measures include network segmentation to limit access to management interfaces and enhanced monitoring for anomalous activity.

If your data may have been exposed

Authentication bypass vulnerabilities that are actively exploited can result in unauthorized access and potential data exposure. Organizations should run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst SD-WAN
WeaknessCWE-287
Added to CISA KEVMay 14, 2026
Federal patch deadlineMay 17, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities