Cisco's Catalyst SD-WAN product line — the Controller, Manager, and underlying SD-WAN software formerly branded vSmart and vManage — had seven separate vulnerabilities confirmed exploited over the past year, ranging from a perfect CVSS 10.0 peering-authentication bypass to lower-severity information disclosure and file-manipulation bugs.
| CVE | CVSS | Component | Added to KEV |
|---|---|---|---|
| CVE-2026-20182 | 10.0 | Catalyst SD-WAN | 14 May 2026 |
| CVE-2026-20127 | 10.0 | SD-WAN Controller/Manager (peering auth) | 25 Feb 2026 |
| CVE-2026-20245 | 7.8 | SD-WAN Manager CLI | 9 Jun 2026 |
| CVE-2022-20775 | 7.8 | SD-WAN CLI privilege escalation | 25 Feb 2026 |
| CVE-2026-20128 | 7.5 | SD-WAN Manager Data Collection Agent | 20 Apr 2026 |
| CVE-2026-20262 | 6.5 | SD-WAN Manager web UI | 15 Jun 2026 |
| CVE-2026-20133 | 6.5 | Catalyst SD-WAN Software | 20 Apr 2026 |
Why one product line producing seven KEV entries in a year is a pattern, not bad luck
Cisco's SD-WAN platform manages exactly the kind of centralized, wide-reach infrastructure discussed elsewhere in this series — a single controller or manager orchestrating an entire fleet of branch-office edge devices. Seven distinct vulnerabilities against it in twelve months, spanning peering authentication, CLI privilege handling, a data collection agent, and the web management interface, describes a product surface broad enough that multiple independent weaknesses were found across nearly every major component of the stack — the controller, the CLI, the management UI, and the underlying data-collection agent.
CVE-2026-20127's peering-authentication bypass is the standout: a flaw in how SD-WAN Controllers and Managers authenticate their own peer-to-peer communication, at a perfect 10.0. An SD-WAN fabric's controllers and managers trust each other implicitly to coordinate routing and policy across every connected branch — a peering authentication bypass potentially lets an attacker insert themselves into that trusted mesh, which is a fundamentally different and more consequential compromise than gaining access to any single edge device.
What to check this week
Patch across the entire SD-WAN Controller and Manager fleet, not selectively. With seven distinct vulnerabilities across a year touching different components, partial remediation focused on whichever CVE prompted the review leaves real exposure in the others.
Give CVE-2026-20127 and CVE-2026-20182 priority given their maximum severity scores — both represent the most severe end of what this cluster describes, and both were confirmed exploited, not merely disclosed.
Review CLI access controls specifically, given that two of the seven CVEs in this cluster (CVE-2026-20245 and CVE-2022-20775) involve the SD-WAN CLI directly, suggesting command-line access deserves particular scrutiny in this product's overall security posture.
Audit SD-WAN Manager web UI and Data Collection Agent exposure, restricting both to the minimum network reachability actually required for legitimate administration and monitoring.
Why the CLI-specific findings deserve independent tracking
CVE-2026-20245 and CVE-2022-20775 both involve command-line access specifically, one via privilege escalation and one via an unspecified CLI vulnerability, and the four-year gap between their original disclosure dates and shared 2026 KEV listing echoes the pattern seen elsewhere in this series where an older finding resurfaces in confirmed exploitation well after its initial disclosure window closed. CLI access, often granted to network operations staff with a lighter provisioning process than web console access, deserves its own access review independent of whatever controls govern the web management interface.
A closing note on SD-WAN's growth trajectory
SD-WAN adoption has grown steadily as organizations replace traditional branch-office routing with centrally managed, software-defined alternatives, meaning the population of organizations exposed to this specific product line's vulnerability history is larger today than it would have been just a few years ago — worth factoring into how much attention this cluster deserves relative to its raw CVE count.
A final consideration on migration timing
Organizations mid-migration from legacy branch routing to Cisco's SD-WAN platform should factor this cluster's findings into their rollout timeline explicitly, ensuring the target platform's own patch level is verified as part of migration planning rather than assumed current simply because it's the newer replacement technology.
How Safeguard helps
Safeguard's continuous inventory tracks SD-WAN and network orchestration infrastructure with the same priority applied to any other management-plane software, recognizing that a product line producing this many confirmed-exploited findings in a single year deserves elevated, ongoing attention rather than a one-time patch response to whichever individual CVE happens to make the most noise.