WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Vulnerability Notification - Critical Vulnerability Affecting Cisco Catalyst SD-WAN, CVE-2026-20182
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability Affecting Cisco Catalyst SD-WAN, CVE-2026-20182

TLP:CLEAR

Author: Chase Snow

Created: Tuesday, May 19, 2026 - 14:00

Categories: Cybersecurity, Security Preparedness

ACTION MAY BE REQUIRED for utilities using Cisco Catalyst SD-WAN Controller or Cisco Catalyst SD-WAN Manager products, including internet-facing SD-WAN management infrastructure. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.

Summary: A critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager is being actively exploited in the wild. Tracked as CVE-2026-20182, the vulnerability carries a CVSS score of 10.0 and could allow an unauthenticated remote attacker to gain administrative privileges on vulnerable systems.

Analyst Note: This vulnerability is particularly concerning for utilities because SD-WAN (Software-Defined Wide Area Network) infrastructure often connects distributed operational environments, remote facilities, and cloud management network infrastructure. A compromised SD-WAN environment could allow attackers to establish unauthorized peer connections, move laterally, and potentially access systems that support operational technology (OT) environments.

Cisco has released software updates to address the vulnerability and stated there are no workarounds that fully mitigate the issue. WaterISAC strongly encourages members to review Cisco’s advisory, validate whether affected systems are internet accessible, and upgrade affected Cisco Catalyst SD-WAN instances to a fixed version immediately.

Additional Reading:

  • CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

Related WaterISAC PIRs: 6, 8, 10

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar