Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Charter Communications data breach affects 4.9 million accounts

    May 30, 2026

    MacGregor Voyage Data Recorder (VDR) G4e

    May 30, 2026

    KMW CCTV Security Cameras | CISA

    May 30, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»Alerts»AL26-012 – Critical vulnerability affecting Cisco Catalyst SD-WAN – CVE-2026-20182
    Alerts

    AL26-012 – Critical vulnerability affecting Cisco Catalyst SD-WAN – CVE-2026-20182

    adminBy adminMay 16, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Number: AL26-012
    Date: May 15, 2026

    Audience

    This Alert is intended for IT professionals and managers.

    Purpose

    An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (“Cyber Centre”) is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

    Details

    The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation1Footnote 2 of Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) devices Footnote 3. In response to the Cisco security advisory released on May 14, 2026Footnote 4, the Cyber Centre issued AV26-471Footnote 5 on May 14, 2026.

    Tracked as CVE-2026-20182 Footnote 6, this vulnerability is a critical Improper authentication vulnerability (CWE-287)Footnote 7 affecting the peering authentication process of Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). It could allow an unauthenticated, remote attacker to bypass authentication, elevate privileges, and obtain administrative privileges on affected systems.

    Cisco Catalyst SD-WAN Controller systems accessible from the internet, particularly those with exposed network ports, are at risk of exposure to compromise.

    This vulnerability affects Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, regardless of device configuration. The vulnerability affects all deployment types, including:

    • On-Prem Deployment
    • Cisco SD-WAN Cloud-Pro
    • Cisco SD-WAN Cloud – Cisco Managed
    • Cisco SD-WAN for Government – FedRAMP Environment

    The Cyber Centre is aware of incidents involving CVE-2026-20182; with reported attempts of SSH keys being added, NETCONF configurations being modified and escalation to root privileges. This allowed multiple follow-up actions including administrative access, persistence and long-term access to SD-WAN networks.

    Cisco has also noted the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 previously reported in February 2026 Footnote 8. The Cyber Centre released AL26-004 Footnote 9 at that time highlighting the issue.

    Suggested actions

    The Cyber Centre recommends that organizations upgrade affected Cisco Catalyst SD-WAN instances to a fixed version:

    Affected product Affected version Solution
    Cisco Catalyst SD-WAN Earlier than 20.9* Migrate to a fixed release.
    Cisco Catalyst SD-WAN 20.9 20.9.9.1
    Cisco Catalyst SD-WAN 20.10 20.12.7.1
    Cisco Catalyst SD-WAN 20.11* 20.12.7.1
    Cisco Catalyst SD-WAN 20.12 20.12.5.4
    20.12.6.2
    20.12.7.1
    Cisco Catalyst SD-WAN 20.13* 20.15.5.2
    Cisco Catalyst SD-WAN 20.14* 20.15.5.2
    Cisco Catalyst SD-WAN 20.15 20.15.4.4
    20.15.5.2
    Cisco Catalyst SD-WAN 20.16* 20.18.2.2
    Cisco Catalyst SD-WAN 20.18* 20.18.2.2
    Cisco Catalyst SD-WAN 26.1 26.1.1.1

    Cisco has also addressed this vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.506, which is cloud based. No user action is required. Customers can determine the current remediation status or software version by using the Help function in the service GUIFootnote 4.

    The Cyber Centre also recommends organizations to:

    • Review the Cisco advisoryFootnote 4 and the Talos Intelligence articleFootnote 1 to identify if indicators of compromise are present on their devices.
    • Cisco states to preserve possible indicators of compromise, customers should issue the request admin-tech command from each of the control components in the SD-WAN deployment before upgradingFootnote 4Footnote 10.
    • Collect artifacts, including virtual snapshots and logs from SD-WAN technology.
    • Fully patch SD-WAN technology including those that are affected by CVE-2026-20182.
    • Implement recommendations from the Cisco SD-WAN hardening guideFootnote 11.

    In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topicsFootnote 12.

    • Consolidating, monitoring, and defending Internet gateways
    • Patch operating systems and applications
    • Harden operating systems and applications
    • Isolate web-facing applications

    Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca.

    References

    *

    These releases have reached End of Software Maintenance.

    Return to footnote* referrer

    Footnote 1

    Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

    Return to footnote1 referrer

    Footnote 2

    Rapid7 CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

    Return to footnote2 referrer

    Footnote 3

    What is SD-WAN? Software-Defined WAN (SDWAN)

    Return to footnote3 referrer

    Footnote 4

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    Return to footnote4 referrer

    Footnote 5

    Cisco security advisory (AV26-471)

    Return to footnote5 referrer

    Footnote 6

    cve.org – CVE-2026-20182

    Return to footnote6 referrer

    Footnote 7

    CWE-287: Improper Authentication

    Return to footnote7 referrer

    Footnote 8

    Cisco Catalyst SD-WAN Vulnerabilities

    Return to footnote8 referrer

    Footnote 9

    AL26-004 – Critical vulnerability affecting Cisco Catalyst SD-WAN – CVE-2026-20127

    Return to footnote9 referrer

    Footnote 10

    Remediate Catalyst SD-WAN Security Advisory – May 2026

    Return to footnote10 referrer

    Footnote 11

    Cisco Catalyst SD-WAN Hardening Guide

    Return to footnote11 referrer

    Footnote 12

    Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)

    Return to footnote12 referrer



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-8657 | THREATINT
    Next Article Avada Builder WordPress plugin flaws allow site credential theft
    admin
    • Website

    Related Posts

    Alerts

    MacGregor Voyage Data Recorder (VDR) G4e

    May 30, 2026
    Alerts

    KMW CCTV Security Cameras | CISA

    May 30, 2026
    Alerts

    CVE-2026-10152 | THREATINT

    May 30, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    Charter Communications data breach affects 4.9 million accounts

    May 30, 2026

    MacGregor Voyage Data Recorder (VDR) G4e

    May 30, 2026

    KMW CCTV Security Cameras | CISA

    May 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.