CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
PatchCisco Catalyst SD-WAN Controller (vSmart) Read at Rapid7 Blog
Below is the opening; the full story is at Rapid7 Blog.
From Rapid7 Blog
Overview
While researching a critical authentication bypass vulnerability, CVE-2026-20127, which was exploited in-the-wild, Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.