CVE-2026-20182

CRITICAL KEV NUCLEI

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-20182 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 14, 2026. EIP tracks 5 public exploits from researchers including Nxploited, HORKimhab, portbuster1337, including a Metasploit module auxiliary/admin/networking/cisco_sdwan_vhub_auth_bypass. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2026-20182, targeting Cisco Catalyst SD-WAN Controller's peering authentication bypass. The script implements a DTLS-based attack to bypass authentication and gain high-privileged internal access.

Description

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.  A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Exploits (5)

github WORKING POC
by Nxploited · remote
https://github.com/Nxploited/CVE-2026-20182

The repository contains a functional Python exploit for CVE-2026-20182, targeting Cisco Catalyst SD-WAN Controller's peering authentication bypass. The script implements a DTLS-based attack to bypass authentication and gain high-privileged internal access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Cisco Catalyst SD-WAN Controller (formerly vSmart) / Cisco Catalyst SD-WAN Manager (formerly vManage)
No auth needed
Prerequisites: Network access to the target system · DTLS port (12346) accessibility
devstral-2 · analyzed May 26, 2026 Full analysis →
github STUB
by HORKimhab · remote
https://github.com/HORKimhab/CVE-2026-20182

The repository contains no actual exploit code or technical details for CVE-2026-20182. It only includes a generic README with legal disclaimers, a LICENSE file, and a template file for CVE IDs.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
devstral-2 · analyzed May 24, 2026 Full analysis →
github WORKING POC
by portbuster1337 · pythonremote
https://github.com/portbuster1337/CVE-2026-20182

This repository contains a functional exploit for CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller/Manager. The exploit leverages a flaw in the vdaemon service (UDP/12346) to bypass authentication by impersonating a vHub device and injects an SSH public key for persistent access.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Cisco Catalyst SD-WAN Controller/Manager (vSmart/vManage) versions < 20.9, 20.9-20.18 (unpatched), 26.1.1 (unpatched)
No auth needed
Prerequisites: Network access to UDP/12346 on the target · DTLS 1.2 support on the target
devstral-2 · analyzed May 23, 2026 Full analysis →
nomisec SUSPICIOUS
by fangbarristerbar · poc
https://github.com/fangbarristerbar/CVE-2026-20182-POC

The repository claims to provide an exploit for CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Controller/Manager, but lacks actual exploit code. Instead, it directs users to an external download link (tinyurl.com), which is a common tactic for malicious or monetized exploits.

Classification
Suspicious 90%
Attack Type
Auth Bypass
Complexity
Theoretical
Reliability
Theoretical
Target: Cisco Catalyst SD-WAN Controller/Manager
No auth needed
Prerequisites: network access to UDP/12346 · target running vulnerable Cisco SD-WAN software
devstral-2 · analyzed May 16, 2026 Full analysis →
metasploit WORKING POC
by sfewer-r7, Crypto-Cat · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/networking/cisco_sdwan_vhub_auth_bypass.rb

This Metasploit module exploits an authentication bypass vulnerability (CVE-2026-20182) in Cisco Catalyst SD-WAN Controller by leveraging a missing verification path for vHub device types in the DTLS handshake process, allowing SSH key injection for persistent access.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Cisco Catalyst SD-WAN Controller 20.12.6.1 and earlier
No auth needed
Prerequisites: Network access to UDP port 12346 · Self-signed certificate for DTLS handshake
devstral-2 · analyzed May 15, 2026 Full analysis →

Nuclei Templates (1)

Cisco Catalyst SD-WAN Controller - vHub Authentication Bypass
CRITICALVERIFIEDby sfewer-r7,Crypto-Cat,pussycat0x,DhiyaneshDk
Shodan: port:12346 product:"Cisco SD-WAN"
FOFA: port="12346" && product="Cisco SD-WAN"

References (3)

Core 3
Core References
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The Indicators of Compromise
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk

Scores

CVSS v3 10.0
EPSS 0.7790
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-05-14
VulnCheck KEV 2026-05-14
ENISA EUVD EUVD-2026-30324
CWE
CWE-287
Status published
Products (50)
cisco/catalyst_sd-wan_manager 20.12.7
cisco/catalyst_sd-wan_manager < 20.9.9.1
Cisco/Cisco Catalyst SD-WAN Controller 17.2.10
Cisco/Cisco Catalyst SD-WAN Controller 17.2.4
Cisco/Cisco Catalyst SD-WAN Controller 17.2.5
Cisco/Cisco Catalyst SD-WAN Controller 17.2.6
Cisco/Cisco Catalyst SD-WAN Controller 17.2.7
Cisco/Cisco Catalyst SD-WAN Controller 17.2.8
Cisco/Cisco Catalyst SD-WAN Controller 17.2.9
Cisco/Cisco Catalyst SD-WAN Controller 18.2.0
... and 40 more
Published May 14, 2026
KEV Added May 14, 2026
Tracked Since May 14, 2026