Cisco Security Advisory
Follow
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
A new security advisory for Cisco Catalyst SD-WAN Controller and Manager was released in May 2026, addressing a critical vulnerability. This vulnerability allows potential attackers to bypass authentication on the system. The vulnerability lies within the peering authentication mechanism of the SD-WAN controller. An unauthenticated attacker could send crafted requests to exploit this flaw. Successful exploitation grants the attacker administrative privileges as a high-privileged non-root user. This compromised account allows access to NETCONF, enabling manipulation of network configurations. Cisco has issued software updates to resolve this vulnerability, with no available workarounds. Customers are advised to gather diagnostic information before upgrading their systems. The advisory provides guidance on identifying potential compromises using "Show Control Connections". Users should upgrade their software as soon as possible after collecting necessary information. This vulnerability is rated as critical and is identified by CVE-2026-20182.