logo

CVE-2026-20182: Unauthenticated Cisco SD-WAN Control-Plane Compromise via vHub Authentication Bypass

ID: 87d2e1d8-f693-5d78-bc7c-e2ebe6310f8d

STIX ID: report--87d2e1d8-f693-5d78-bc7c-e2ebe6310f8d

Feed Name: Resecurity

Threat Score
95/100

Date Published: 2026-05-18

Date Updated: 2026-07-27

...
...

CVE-2026-20182 is a critical authentication-bypass in Cisco Catalyst SD‑WAN vdaemon (CVSS 10.0) whereby an attacker can establish a DTLS session, send a crafted CHALLENGE_ACK claiming device_type=2 (vHub) to bypass certificate and identity validation, be marked authenticated, and then perform privileged actions including injecting SSH keys into /home/vmanage-admin/.ssh/authorized_keys and gaining NETCONF access; Cisco has released fixed software releases and advises immediate patching as no configuration workaround fully mitigates the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.