CVE-2026-20182 (CVSS 10.0): Cisco Catalyst SD-WAN Auth Bypass Actively Exploited — Patch Now
A perfect-10 authentication bypass in Cisco's SD-WAN control plane is being exploited in the wild by nation-state group UAT-8616. No credentials needed to seize full fabric control.
Cisco disclosed CVE-2026-20182 on May 14, 2026 — a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller (formerly vSmart) and SD-WAN Manager (formerly vManage). CISA added it to the Known Exploited Vulnerabilities catalog the same day it went public.
What the vulnerability does
The flaw lives in the vdaemon service, which listens on UDP port 12346 using DTLS. A crafted packet sequence bypasses authentication entirely, granting the attacker a high-privileged internal user session — without any credentials. From there, they can manipulate the NETCONF interface to reconfigure the entire SD-WAN fabric: rerouting traffic, injecting routes, or silently intercepting data crossing corporate WAN links.
This is a control-plane compromise, not just a single device takeover. One exploit packet can hand an attacker administrative authority over every edge site connected to the controller.
Active exploitation
Rapid7 researchers Stephen Fewer and Jonah Burgess discovered the bug and first contacted Cisco on March 9, 2026. Cisco’s PSIRT requested a delayed disclosure to May 14 — coordinated. In that window, the threat actor UAT-8616 (linked to a nation-state) was already exploiting it alongside a related flaw, CVE-2026-20127.
UAT-8616 is the same group behind recent intrusions into enterprise SD-WAN infrastructure across financial and critical-infrastructure sectors. Cisco confirmed “limited exploitation in the wild” in its advisory, which typically means targeted attacks rather than mass scanning — for now.
Affected versions and fix
All Cisco Catalyst SD-WAN Controller and SD-WAN Manager releases before the patched builds are vulnerable. Cisco has released fixed software; there is no workaround that fully mitigates the issue. The only safe path is upgrading.
Check your version against Cisco Security Advisory cisco-sa-sdwan-rpa2-v69WY2SW on Cisco’s Security Center. If you are running the vManage or vSmart personas on Cisco SD-WAN, treat this as a zero-day until you’re on the patched release.
What to do right now
- Pull the fixed software from Cisco’s download portal immediately.
- Audit DTLS traffic logs on UDP 12346 going back 60 days — UAT-8616 was active before disclosure.
- Check NETCONF audit logs for unexpected configuration changes.
- If upgrading will take longer than 24 hours, place the controller behind a strict firewall ACL that allows only trusted orchestrator IPs on port 12346.
A CVSS 10.0 against a network control plane is about as serious as it gets. The combination of active nation-state exploitation and same-day KEV listing means “patch next maintenance window” is the wrong read here.
Related reading
- Cybersecurity Cisco's 7th SD-WAN Zero-Day of 2026: CVE-2026-20245 Enables Root Execution — No Patch Available
- Cybersecurity CISA Adds 8 Actively Exploited Flaws to KEV, Including Three Cisco SD-WAN Zero-Days
- Cybersecurity Broadcom Patches Two Critical vCenter Flaws (CVSS 9.8) and an ESXi VM-Escape Bug — No Workarounds Available