Cisco warns that a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller is being exploited in the wild as a zero-day. The flaw, tracked as CVE-2026-20182 and rated CVSS 10.0, affects the peering authentication mechanism used by Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN Manager). Because the issue occurs in authentication, successful exploitation can allow attackers to gain administrative privileges on affected devices or gain admin access through the SD-WAN management/control components. Multiple outlets report Cisco has released patches to address the problem and that exploitation is not limited to a single campaign, with reporting indicating “limited” activity in some cases and “zero-day” exploitation by a sophisticated threat actor. Coverage also notes this is the second time this year Cisco has faced a maximum-severity (CVSS 10.0) vulnerability leveraged by threat actors in its network control system. The affected functionality involves the peering relationship used for SD-WAN operations, and the issue is reported to impact both on-premises and cloud deployments. Cisco’s guidance focuses on applying the released updates to mitigate the risk of administrative compromise.