Known vulnerability record
CVE-2026-20182
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Summary
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Signals
Keep the signals separate
CVSS severitycriticalScore 10 · source cisco
EPSS probability91.5%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-05-14
Ransomware useunknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2026-05-14
- CVE modified
- 2026-06-16
- KEV date added
- 2026-05-14
- Dataset fetched
- 2026-08-21T03:55:09.229Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2026-20182 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2026-20182 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20182 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.