DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

Cisco SD-WAN 20.9 Leaves Security Support on September 30, 2026

Cisco fixed seven exploited Catalyst SD-WAN flaws on the 20.9 line this year. Its End of Vulnerability/Security Support is September 30, 2026.

Seven exploited flaws, seven 20.9 fixes

CVE What it is CVSS Added to CISA KEV First fixed 20.9 build
CVE-2026-20127 Peering authentication bypass on SD-WAN Controller, Manager and Validator; unauthenticated, remote 10.0 February 25, 2026 20.9.8.2
CVE-2026-20128 Data Collection Agent credential file lets an unauthenticated attacker gain DCA user privileges on SD-WAN Manager 7.5 April 20, 2026 20.9.8.2
CVE-2026-20122 Arbitrary file overwrite through the SD-WAN Manager API; needs read-only API credentials 5.4 April 20, 2026 20.9.8.2
CVE-2026-20133 Insufficient file-system restrictions expose sensitive files to an authenticated netadmin user 6.5 April 20, 2026 20.9.8.2
CVE-2026-20182 Second authentication bypass, in control-connection handshaking, found and fixed after the February disclosure 10.0 May 14, 2026 20.9.9.1
CVE-2026-20245 CLI privilege escalation to root for an authenticated local netadmin; Cisco saw it used after CVE-2026-20182 or CVE-2026-20127 7.8 June 9, 2026 20.9.9.2
CVE-2026-20262 Arbitrary file write through the SD-WAN Manager web UI; authenticated, remote 6.5 June 15, 2026 20.9.9.2

What's covered

  • Seven exploited flaws, seven 20.9 fixes
  • What the same advisories say about lines outside the window
  • Where a 20.9 fabric goes next
  • What to do before the date

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-cisco-sdwan-20-9-security-support-ends-2026

Top comments (0)