Cisco
Catalyst SD-WAN
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This CVE identity is linked to the Lifecycle record Cisco Catalyst SD-WAN. Use that record for publisher support phases and retirement dates.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-20182 | 14 May 2026 | Cisco Catalyst SD-WAN Controller: 20.6.4, 20.9.2, 20.3.6, 20.7.2, 20.7.1, 20.5.1, 20.6.2, 19.3.0, 20.6.1, 17.2.4, 18.2.0, 18.4.6, 19.1.0, 19.2.4, 19.2.929, 18.3.8, 18.4.303, 18.3.7, 18.4.1, 19.2.097, 19.2.0, 19.2.099, 18.3.6, 20.4.2, 19.0.0, 20.9.1, 20.3.5, 20.3.1, 18.3.5, 20.6.3, 18.4.3, 18.4.4, 18.3.3, 17.2.8, 20.8.1, 19.2.32, 19.2.2, 17.2.5, 18.4.0, 20.4.1.1, 20.1.3, 20.1.2, 17.2.10, 19.2.098, 20.1.1, 17.2.6, 19.2.1, 18.3.4, 20.4.1, 17.2.9, 19.2.31, 19.0.1a, 18.3.0, 17.2.7, 18.4.5, 20.3.4, 20.3.3, 20.4.1.2, 20.3.2, 18.3.1, 20.1.12, 19.2.3, 20.10.1, 20.6.5, 20.3.7, 20.9.3, 20.11.1, 20.6.3.2, 20.4.2.3, 20.3.5.1, 20.3.4.3, 20.9.3.1, 20.6.4.1, 20.3.3.2, 20.6.5.2, 20.3.7.1, 20.11.1.1, 20.10.1.1, 20.6.1.2, 20.1.3.1, 20.9.2.2, 20.6.5.3, 20.6.3.3, 20.3.7.2, 20.6.5.4, 20.9.2.3, 20.9.4, 20.12.1, 20.3.8, 20.6.6, 20.12.2, 20.13.1, 20.9.5, 20.12.3, 20.6.7, 20.9.5.1, 20.14.1, 20.12.3.1, 20.12.4, 20.15.1, 20.9.6, 20.6.8, 20.16.1, 20.9.5.3, 20.12.4.1, 20.15.2, 20.12.5, 20.9.7, 20.15.3, 20.12.5.1, 20.12.5.2, 20.15.4, 20.9.7.1, 20.12.6, 20.9.8, 20.15.4.1, 20.15.4.2, 20.12.5.3, 20.12.6.1, 20.9.8.2, 20.15.5, 20.12.7, 20.9.9, 20.15.5.1, 20.15.4.3, 20.15.4.5, 20.15.5.3, 20.12.7.2, 20.9.9.2; Cisco Catalyst SD-WAN Manager: 20.1.12, 19.2.1, 18.4.4, 18.4.5, 20.1.1.1, 20.1.1, 19.2.099, 18.3.6, 18.3.7, 19.2.0, 19.1.0, 18.4.303, 19.2.098, 18.3.6.1, 18.2.0, 17.2.8, 18.3.3.1, 18.4.0, 18.3.1, 17.2.6, 17.2.9, 17.2.5, 18.4.0.1, 18.3.3, 18.3.0, 19.2.3, 18.4.501_ES, 20.1.2, 19.2.929, 19.2.31, 20.3.2, 19.2.4, 19.2.4.0.9, 20.1.3.1 | The Cyber Centre recommends that organizations upgrade affected Cisco Catalyst SD-WAN instances to a fixed version: Affected product Affected version Solution Cisco Catalyst SD-WAN Earlier than 20.9 * Migrate to a fixed release. Cisco Catalyst SD-WAN 20.9 20.9.9.1 Cisco Catalyst SD-WAN 20.10 20.12.7.1 Cisco Catalyst SD-WAN 20.11 * 20.12.7.1 Cisco Catalyst SD-WAN 20.12 20.12.5.4 20.12.6.2 20.12.7.1 Cisco Catalyst SD-WAN 20.13 * 20.15.5.2 Cisco Catalyst SD-WAN 20.14 * 20.15.5.2 Cisco Catalyst SD-WAN 20.15 20.15.4.4 20.15.5.2 Cisco Catalyst SD-WAN 20.16 * 20.18.2.2 Cisco Catalyst SD-WAN 20.18 * 20.18.2.2 Cisco Catalyst SD-WAN 26.1 26.1.1.1 Cisco has also addressed this vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.506, which is cloud based. No user action is required. Customers can determine the current remediation status or software version by using the Help function in the service GUI Footnote 4 . The Cyber Centre also recommends organizations to: Review the Cisco advisory Footnote 4 and the Talos Intelligence article Footnote 1 to identify if indicators of compromise are present on their devices. Cisco states to preserve possible indicators of compromise, customers should issue the request admin-tech command from each of the control components in the SD-WAN deployment before upgrading Footnote 4 Footnote 10 . Collect artifacts, including virtual snapshots and logs from SD-WAN technology. Fully patch SD-WAN technology including those that are affected by CVE-2026-20182. Implement recommendations from the Cisco SD-WAN hardening guide Footnote 11 . In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topics Footnote 12 . Consolidating, monitoring, and defending Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca . | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.