endoflife.ai
Cisco Catalyst SD-WAN EOS Edge Device List Exploited & Unpatchable EOL Watch

Cisco SD-WAN 20.9 Leaves Security Support on September 30, 2026

By Scott Bissett  ·  Published: September 13, 2026  ·  EOL Watch — deadline analysis  ·  Read at Cisco's 20.9.x end-of-life bulletin, Cisco's five 2026 SD-WAN security advisories and CISA's catalog; lifecycle dates from Cisco's per-release bulletins.

Cisco Catalyst SD-WAN had a bad 2026, and the 20.9 line came through it patched every time. CISA added seven Catalyst SD-WAN vulnerabilities to its Known Exploited Vulnerabilities catalog between February and June, two of them CVSS 10.0 authentication bypasses on the controllers that hold the fabric together. Cisco's advisory for every one of the seven lists a fixed 20.9 build: 20.9.8.2, then 20.9.9.1, then 20.9.9.2. That happened for one reason. 20.9 was still inside the window Cisco calls End of Vulnerability/Security Support.

That window closes on September 30, 2026. Cisco's end-of-life bulletin for SD-WAN Release 20.9.x, whose End-of-Life Announcement Date is September 30, 2023, sets three dates: End of Software Maintenance Releases on March 30, 2025, End of Vulnerability/Security Support on September 30, 2026, and Last Date of Support on March 30, 2027. The bulletin's own words for what follows the middle date: bug fixes for vulnerability or security issues identified in 20.9 "may be provided through later supported software releases", and "there will be no rebuild releases" of 20.9 after it. The eighth exploited flaw on this product, whenever it comes, will have a fixed build for 20.12, 20.15, 20.18 and 26.1. It will not have one for 20.9.
Quick answer: Cisco Catalyst SD-WAN 20.9 is supported until September 30, 2026, its end-of-support date. Active support for Cisco Catalyst SD-WAN 20.9 ends on March 30, 2025; security fixes continue until that end-of-life date. It is also the next Cisco Catalyst SD-WAN version to reach end of life. 15 of 20 tracked Cisco Catalyst SD-WAN versions are past end of life; the most recent to reach it, 20.16, did so on January 13, 2026. Every Cisco Catalyst SD-WAN version's release and end-of-support date is on the Cisco Catalyst SD-WAN lifecycle page.

Seven exploited flaws, seven 20.9 fixes

The table is Cisco's fixed-release rows for the 20.9 line, taken from the five advisories, against CISA's catalog dates. The CVSS scores are Cisco's. The fixed builds are the "First Fixed Release" Cisco lists for 20.9; the advisories for CVE-2026-20245 and CVE-2026-20262 phrase the row as "20.9.9.1 and earlier" fixed in 20.9.9.2.

CVEWhat it isCVSSAdded to CISA KEVFirst fixed 20.9 build
CVE-2026-20127Peering authentication bypass on SD-WAN Controller, Manager and Validator; unauthenticated, remote10.0February 25, 202620.9.8.2
CVE-2026-20128Data Collection Agent credential file lets an unauthenticated attacker gain DCA user privileges on SD-WAN Manager7.5April 20, 202620.9.8.2
CVE-2026-20122Arbitrary file overwrite through the SD-WAN Manager API; needs read-only API credentials5.4April 20, 202620.9.8.2
CVE-2026-20133Insufficient file-system restrictions expose sensitive files to an authenticated netadmin user6.5April 20, 202620.9.8.2
CVE-2026-20182Second authentication bypass, in control-connection handshaking, found and fixed after the February disclosure10.0May 14, 202620.9.9.1
CVE-2026-20245CLI privilege escalation to root for an authenticated local netadmin; Cisco saw it used after CVE-2026-20182 or CVE-2026-201277.8June 9, 202620.9.9.2
CVE-2026-20262Arbitrary file write through the SD-WAN Manager web UI; authenticated, remote6.5June 15, 202620.9.9.2

CISA's catalog carries an eighth Catalyst SD-WAN entry, CVE-2022-20775, a local privilege escalation added on the same day as CVE-2026-20127. Cisco's affected list for it stops at the 20.7 line, so it is outside 20.9's story and outside this table.

Read the exploitation lines in the advisories and the pattern is the same each time. Cisco's PSIRT "is aware of limited exploitation" of CVE-2026-20127, reported to Cisco by the Australian Signals Directorate's cyber security centre. Active exploitation of CVE-2026-20128 and CVE-2026-20122 was known to Cisco in March; CVE-2026-20133 was added to that list in April. Exploitation of CVE-2026-20182 was known in May, of CVE-2026-20245 and CVE-2026-20262 in June. Two of the five advisories were revised in June to add the SD-WAN Validator to the affected products. Every revision, every new CVE, every escalation of an exploitation note got a 20.9 build. That is what a line inside its security window looks like from the outside.

Running Cisco Catalyst SD-WAN past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Cisco Catalyst SD-WAN is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

What the same advisories say about lines outside the window

The fixed-release tables in the February and May advisories have a second kind of row. 20.11, 20.13, 20.14 and 20.16 appear with a footnote, "These releases have reached End of Software Maintenance", and their fix is a later line: 20.12.6.1, 20.15.4.2, 20.18.2.1. By June, Cisco's tables for CVE-2026-20245 and CVE-2026-20262 list five lines and no footnotes: 20.9, 20.12, 20.15, 20.18 and 26.1. The other lines are not in the table at all. Their lifecycle dates, from Cisco's bulletins as we serve them on the Catalyst SD-WAN page:

ReleaseEnd of SW Maintenance ReleasesEnd of Vulnerability/Security SupportLast Date of SupportIn Cisco's June 2026 fix tables?
20.16January 13, 2026January 13, 2026July 15, 2028No
20.14May 30, 2025May 30, 2025November 30, 2027No
20.13December 30, 2024December 30, 2024June 30, 2027No
20.11May 14, 2024May 14, 2024November 30, 2026No
20.9March 30, 2025September 30, 2026March 30, 2027Yes, until the middle date passes

Notice what the first four rows have in common. For each of them the End of Software Maintenance date and the End of Vulnerability/Security Support date are the same day, so the line lost bug fixes and security fixes together. 20.9 was given a longer security tail, eighteen months past its maintenance end, and Cisco used every month of it. The Last Date of Support in the fourth column is a different thing again: it is the date service contracts stop, and it never brought a fix to any of these lines.

Where a 20.9 fabric goes next

Cisco's June tables answer that question by listing the lines it still fixes. On Cisco's bulletins:

ReleaseEnd of SW Maintenance ReleasesEnd of Vulnerability/Security SupportLast Date of SupportJune 2026 fixed build (CVE-2026-20245, CVE-2026-20262)
20.12March 30, 2026September 30, 2027March 31, 202820.12.7.2
20.15March 30, 2027September 30, 2028March 30, 202920.15.4.5 and 20.15.5.3
20.18No bulletin yetNo bulletin yetNo bulletin yet20.18.3.1
26.1No bulletin yetNo bulletin yetNo bulletin yet26.1.1.2

20.12 is the cautionary row. Its End of Software Maintenance passed in March, and Cisco still shipped 20.12.7.1 in May and 20.12.7.2 in June, exactly as the bulletin language allows: after maintenance ends, security fixes continue until the security date. Its security date is a year after 20.9's. A fabric that moves from 20.9 to 20.12 buys twelve months. 20.15 buys two years. 20.18 and 26.1 have no bulletin at all, which on Cisco's cadence means the longest runway, at the cost of the newest code. Cisco's May advisory points to its Catalyst SD-WAN Upgrade Matrix for the supported path from a given 20.9 build; not every jump is direct.

What we are not saying. We are not saying 20.9 is unpatched today. As of this article every exploited flaw Cisco has disclosed on the product has a 20.9 fix, and a controller on 20.9.9.2 is current for all seven. We are not saying Cisco will refuse a 20.9 fix on October 1; we are quoting the bulletin's own terms, which say fixes "may be provided through later supported software releases" after the date. What the record shows is that Cisco's 2026 advisories have treated every line past its security date the same way: a migrate row, then no row. The date in this article's title is when 20.9 joins them.

What to do before the date

If you are on 20.9 and current: you have a fixed build for everything disclosed so far and security coverage until September 30, 2026. Choose the target line now and schedule the controllers first; the Manager, Controller and Validator are where the two CVSS 10.0 flaws lived, and they are what an attacker reaches from outside.

If you are on 20.9 and not current: 20.9.9.2 closes all seven exploited flaws and is the last stop on the line worth making before the migration. Cisco's advisories for CVE-2026-20128 and CVE-2026-20182 also describe indicators of compromise and, for the February flaws, a documented rebuild procedure; read them before you trust a controller that sat exposed.

If you are on 20.11, 20.13, 20.14 or 20.16: you are already where 20.9 is about to be. Cisco's tables have said "migrate to a fixed release" for those lines all year.

Everyone: the Catalyst SD-WAN page carries every release with its three Cisco milestones, and the dates on this page are bound to that data and refresh at every build. Watch 20.12's End of Software Maintenance, which has already passed, as the marker for how Cisco's bulletins behave: a line keeps getting security fixes after that date, and stops at the next one.

Frequently Asked Questions

When does Cisco Catalyst SD-WAN 20.9 reach end of support?

Cisco's end-of-life bulletin for SD-WAN Release 20.9.x sets End of Software Maintenance Releases on March 30, 2025, End of Vulnerability/Security Support on September 30, 2026 and Last Date of Support on March 30, 2027. After the security date Cisco Engineering may no longer release security fixes for 20.9; the bulletin says fixes for issues found in 20.9 may be provided through later supported releases.

Did Cisco fix the 2026 exploited SD-WAN vulnerabilities on 20.9?

Yes, all seven. Cisco's advisories list a fixed 20.9 build for each of the seven Catalyst SD-WAN entries CISA added to its Known Exploited Vulnerabilities catalog in 2026: 20.9.8.2 for CVE-2026-20127, CVE-2026-20128, CVE-2026-20122 and CVE-2026-20133; 20.9.9.1 for CVE-2026-20182; and 20.9.9.2 for CVE-2026-20245 and CVE-2026-20262. Those fixes shipped because 20.9 was still inside its End of Vulnerability/Security Support window.

Which Cisco SD-WAN release should 20.9 customers move to?

Cisco's June 2026 advisories list fixed builds for four lines besides 20.9: 20.12, 20.15, 20.18 and 26.1. On Cisco's bulletins as we serve them, 20.12's End of Vulnerability/Security Support is September 30, 2027 and 20.15's is September 30, 2028; 20.18 and 26.1 have no end-of-life bulletin yet. Check Cisco's Catalyst SD-WAN Upgrade Matrix for the supported path from your 20.9 build.

Is Cisco SD-WAN 20.9 still supported after September 30, 2026?

For technical assistance, yes, until the Last Date of Support on March 30, 2027. For security fixes, no. Cisco's bulletin language is that after the End of Vulnerability/Security Support date there will be no rebuild releases of 20.9 and fixes may be provided through later supported software releases. A 20.9 controller or manager is then in the position 20.11, 20.13, 20.14 and 20.16 already occupy in Cisco's 2026 advisories: a migrate-to-a-fixed-release row, and then no row.

Related

© 2026 endoflife.ai · How we verify our dates · API · About