---
schema: 1
kind: vulnerability
title: "CVE-2026-20182 — Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeover"
headline: "CVE-2026-20182 — Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeover"
summary: "Cisco Catalyst SD-WAN Controller CVE-2026-20182 (CVSS 10.0, pre-auth) actively exploited by UAT-8616; at least 10 additional opportunistic clusters are exploiting companion February 2026 CVEs (CVE-2026-20133/128/122) on the same infrastructure; CISA Emergency Directive ED-26-03 issued 2026-05-14; no workaround — patch now (Cisco Talos, 2026-05-14)."
discovered_at: "2026-05-15T05:00:05Z"
event_date: 2026-05-14
run_id: 2026-05-15-58b94fbd
priority: critical
immediate_action:
  title: "Patch Cisco Catalyst SD-WAN Controller and Manager now (CVE-2026-20182, CVSS 10.0)"
  action: "The vdaemon service's DTLS peering handshake lacks device-type validation, enabling any attacker with network reach to UDP/12346 to inject SSH keys and assume full administrative control of the SD-WAN fabric without credentials. There is no workaround; only upgrading to a fixed release (e.g., 20.9.9.1, 20.12.7.1, 20.15.5.2, 20.18.2.2) removes the attack surface."
tags:
  - actively-exploited
  - pre-auth
  - rce
  - cisa-kev
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-20182
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW"
    publisher: Cisco PSIRT advisory cisco-sa-sdwan-rpa2-v69WY2SW
    role: primary
  - url: "https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/"
    publisher: "Rapid7, 2026-05-14"
    role: corroborating
  - url: "https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems"
    publisher: "CISA ED-26-03, 2026-05-14"
    role: corroborating
closed_sources: []
evidence:
  - quote: "CVE-2026-20182 (CVSS 10.0, CWE-287) is a complete authentication bypass in the vdaemon service's DTLS control-plane peering on UDP/12346 (Cisco PSIRT cisco-sa-sdwan-rpa2-v69WY2SW, 2026-05-14 · Rapid7, 2026-05-14)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-15.md
---

CVE-2026-20182 (CVSS 10.0, CWE-287) is a complete authentication bypass in the `vdaemon` service's DTLS control-plane peering on UDP/12346 ([Cisco PSIRT cisco-sa-sdwan-rpa2-v69WY2SW, 2026-05-14](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW) · [Rapid7, 2026-05-14](https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/)). The `vbond_proc_challenge_ack()` function processes CHALLENGE_ACK messages without checking the claimed device type: a connecting device claiming type 2 (vHub) using a self-signed certificate is unconditionally marked as authenticated. The attacker then sends `MSG_VMANAGE_TO_PEER` (message type 14) to inject an SSH public key into `/home/vmanage-admin/.ssh/authorized_keys`, achieving persistent SSH access to the SD-WAN Manager on NETCONF port TCP/830. From there, the attacker has full control of SD-WAN fabric configuration, routing policy, and can read or modify all managed-site configurations. Added to CISA KEV on 2026-05-14 with active exploitation confirmed. No workaround exists; network segmentation of the UDP/12346 interface is the only partial mitigation where upgrading is not immediately possible. Fixed: 20.9.9.1, 20.12.5.4/6.2/7.1, 20.15.4.4/5.2, 20.18.2.2, 26.1.1.1.
