Safeguard
Vulnerability Analysis

Cisco's Catalyst SD-WAN Line Produced Seven Confirmed-Exploited CVEs in a Year

From a perfect-10 peering authentication bypass to CLI privilege escalation, seven distinct vulnerabilities across Cisco's SD-WAN Controller, Manager, and underlying software were confirmed exploited.

Safeguard Research Team
4 min read

Cisco's Catalyst SD-WAN product line — the Controller, Manager, and underlying SD-WAN software formerly branded vSmart and vManage — had seven separate vulnerabilities confirmed exploited over the past year, ranging from a perfect CVSS 10.0 peering-authentication bypass to lower-severity information disclosure and file-manipulation bugs.

CVECVSSComponentAdded to KEV
CVE-2026-2018210.0Catalyst SD-WAN14 May 2026
CVE-2026-2012710.0SD-WAN Controller/Manager (peering auth)25 Feb 2026
CVE-2026-202457.8SD-WAN Manager CLI9 Jun 2026
CVE-2022-207757.8SD-WAN CLI privilege escalation25 Feb 2026
CVE-2026-201287.5SD-WAN Manager Data Collection Agent20 Apr 2026
CVE-2026-202626.5SD-WAN Manager web UI15 Jun 2026
CVE-2026-201336.5Catalyst SD-WAN Software20 Apr 2026

Why one product line producing seven KEV entries in a year is a pattern, not bad luck

Cisco's SD-WAN platform manages exactly the kind of centralized, wide-reach infrastructure discussed elsewhere in this series — a single controller or manager orchestrating an entire fleet of branch-office edge devices. Seven distinct vulnerabilities against it in twelve months, spanning peering authentication, CLI privilege handling, a data collection agent, and the web management interface, describes a product surface broad enough that multiple independent weaknesses were found across nearly every major component of the stack — the controller, the CLI, the management UI, and the underlying data-collection agent.

CVE-2026-20127's peering-authentication bypass is the standout: a flaw in how SD-WAN Controllers and Managers authenticate their own peer-to-peer communication, at a perfect 10.0. An SD-WAN fabric's controllers and managers trust each other implicitly to coordinate routing and policy across every connected branch — a peering authentication bypass potentially lets an attacker insert themselves into that trusted mesh, which is a fundamentally different and more consequential compromise than gaining access to any single edge device.

What to check this week

Patch across the entire SD-WAN Controller and Manager fleet, not selectively. With seven distinct vulnerabilities across a year touching different components, partial remediation focused on whichever CVE prompted the review leaves real exposure in the others.

Give CVE-2026-20127 and CVE-2026-20182 priority given their maximum severity scores — both represent the most severe end of what this cluster describes, and both were confirmed exploited, not merely disclosed.

Review CLI access controls specifically, given that two of the seven CVEs in this cluster (CVE-2026-20245 and CVE-2022-20775) involve the SD-WAN CLI directly, suggesting command-line access deserves particular scrutiny in this product's overall security posture.

Audit SD-WAN Manager web UI and Data Collection Agent exposure, restricting both to the minimum network reachability actually required for legitimate administration and monitoring.

Why the CLI-specific findings deserve independent tracking

CVE-2026-20245 and CVE-2022-20775 both involve command-line access specifically, one via privilege escalation and one via an unspecified CLI vulnerability, and the four-year gap between their original disclosure dates and shared 2026 KEV listing echoes the pattern seen elsewhere in this series where an older finding resurfaces in confirmed exploitation well after its initial disclosure window closed. CLI access, often granted to network operations staff with a lighter provisioning process than web console access, deserves its own access review independent of whatever controls govern the web management interface.

A closing note on SD-WAN's growth trajectory

SD-WAN adoption has grown steadily as organizations replace traditional branch-office routing with centrally managed, software-defined alternatives, meaning the population of organizations exposed to this specific product line's vulnerability history is larger today than it would have been just a few years ago — worth factoring into how much attention this cluster deserves relative to its raw CVE count.

A final consideration on migration timing

Organizations mid-migration from legacy branch routing to Cisco's SD-WAN platform should factor this cluster's findings into their rollout timeline explicitly, ensuring the target platform's own patch level is verified as part of migration planning rather than assumed current simply because it's the newer replacement technology.

How Safeguard helps

Safeguard's continuous inventory tracks SD-WAN and network orchestration infrastructure with the same priority applied to any other management-plane software, recognizing that a product line producing this many confirmed-exploited findings in a single year deserves elevated, ongoing attention rather than a one-time patch response to whichever individual CVE happens to make the most noise.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.