CVE-2026-20127

CRITICAL(10.0)KEVLikely Exploited

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Description

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

KEV Information

Vendor
Cisco
Product
Catalyst SD-WAN Controller and Manager
Date Added
February 25, 2026
Due Date
February 27, 2026
Required Action
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0

CWEs

Affected Products

VendorProductVersion
ciscocatalyst sd-wan manager< 20.9.8.2; >= 20.11, < 20.12.5.3; >= 20.13, < 20.15.4.2; >= 20.16, < 20.18.2.1; 20.12.6
ciscosd-wan vbond orchestrator< 20.9.8.2; >= 20.11, < 20.12.5.3; >= 20.13, < 20.15.4.2; >= 20.16, < 20.18.2.1; 20.12.6
ciscosd-wan vsmart controller< 20.9.8.2; >= 20.11, < 20.12.5.3; >= 20.13, < 20.15.4.2; >= 20.16, < 20.18.2.1; 20.12.6

Multiple CVSS Assessments

Source: [email protected](Secondary)
10.0
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Source: [email protected](Primary)
10.0
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References

CVSS Score

10.0
CRITICAL(10.0)

EPSS Score

EPSS Score88.24%
EPSS Percentile99.8%

Dates

PublishedFebruary 25, 2026
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.