Cisco SD-WAN 20.9 Leaves Security Support on September 30, 2026
Cisco Catalyst SD-WAN had a bad 2026, and the 20.9 line came through it patched every time. CISA added seven Catalyst SD-WAN vulnerabilities to its Known Exploited Vulnerabilities catalog between February and June, two of them CVSS 10.0 authentication bypasses on the controllers that hold the fabric together. Cisco's advisory for every one of the seven lists a fixed 20.9 build: 20.9.8.2, then 20.9.9.1, then 20.9.9.2. That happened for one reason. 20.9 was still inside the window Cisco calls End of Vulnerability/Security Support.
Seven exploited flaws, seven 20.9 fixes
The table is Cisco's fixed-release rows for the 20.9 line, taken from the five advisories, against CISA's catalog dates. The CVSS scores are Cisco's. The fixed builds are the "First Fixed Release" Cisco lists for 20.9; the advisories for CVE-2026-20245 and CVE-2026-20262 phrase the row as "20.9.9.1 and earlier" fixed in 20.9.9.2.
| CVE | What it is | CVSS | Added to CISA KEV | First fixed 20.9 build |
|---|---|---|---|---|
| CVE-2026-20127 | Peering authentication bypass on SD-WAN Controller, Manager and Validator; unauthenticated, remote | 10.0 | February 25, 2026 | 20.9.8.2 |
| CVE-2026-20128 | Data Collection Agent credential file lets an unauthenticated attacker gain DCA user privileges on SD-WAN Manager | 7.5 | April 20, 2026 | 20.9.8.2 |
| CVE-2026-20122 | Arbitrary file overwrite through the SD-WAN Manager API; needs read-only API credentials | 5.4 | April 20, 2026 | 20.9.8.2 |
| CVE-2026-20133 | Insufficient file-system restrictions expose sensitive files to an authenticated netadmin user | 6.5 | April 20, 2026 | 20.9.8.2 |
| CVE-2026-20182 | Second authentication bypass, in control-connection handshaking, found and fixed after the February disclosure | 10.0 | May 14, 2026 | 20.9.9.1 |
| CVE-2026-20245 | CLI privilege escalation to root for an authenticated local netadmin; Cisco saw it used after CVE-2026-20182 or CVE-2026-20127 | 7.8 | June 9, 2026 | 20.9.9.2 |
| CVE-2026-20262 | Arbitrary file write through the SD-WAN Manager web UI; authenticated, remote | 6.5 | June 15, 2026 | 20.9.9.2 |
CISA's catalog carries an eighth Catalyst SD-WAN entry, CVE-2022-20775, a local privilege escalation added on the same day as CVE-2026-20127. Cisco's affected list for it stops at the 20.7 line, so it is outside 20.9's story and outside this table.
Read the exploitation lines in the advisories and the pattern is the same each time. Cisco's PSIRT "is aware of limited exploitation" of CVE-2026-20127, reported to Cisco by the Australian Signals Directorate's cyber security centre. Active exploitation of CVE-2026-20128 and CVE-2026-20122 was known to Cisco in March; CVE-2026-20133 was added to that list in April. Exploitation of CVE-2026-20182 was known in May, of CVE-2026-20245 and CVE-2026-20262 in June. Two of the five advisories were revised in June to add the SD-WAN Validator to the affected products. Every revision, every new CVE, every escalation of an exploitation note got a 20.9 build. That is what a line inside its security window looks like from the outside.
What the same advisories say about lines outside the window
The fixed-release tables in the February and May advisories have a second kind of row. 20.11, 20.13, 20.14 and 20.16 appear with a footnote, "These releases have reached End of Software Maintenance", and their fix is a later line: 20.12.6.1, 20.15.4.2, 20.18.2.1. By June, Cisco's tables for CVE-2026-20245 and CVE-2026-20262 list five lines and no footnotes: 20.9, 20.12, 20.15, 20.18 and 26.1. The other lines are not in the table at all. Their lifecycle dates, from Cisco's bulletins as we serve them on the Catalyst SD-WAN page:
| Release | End of SW Maintenance Releases | End of Vulnerability/Security Support | Last Date of Support | In Cisco's June 2026 fix tables? |
|---|---|---|---|---|
| 20.16 | January 13, 2026 | January 13, 2026 | July 15, 2028 | No |
| 20.14 | May 30, 2025 | May 30, 2025 | November 30, 2027 | No |
| 20.13 | December 30, 2024 | December 30, 2024 | June 30, 2027 | No |
| 20.11 | May 14, 2024 | May 14, 2024 | November 30, 2026 | No |
| 20.9 | March 30, 2025 | September 30, 2026 | March 30, 2027 | Yes, until the middle date passes |
Notice what the first four rows have in common. For each of them the End of Software Maintenance date and the End of Vulnerability/Security Support date are the same day, so the line lost bug fixes and security fixes together. 20.9 was given a longer security tail, eighteen months past its maintenance end, and Cisco used every month of it. The Last Date of Support in the fourth column is a different thing again: it is the date service contracts stop, and it never brought a fix to any of these lines.
Where a 20.9 fabric goes next
Cisco's June tables answer that question by listing the lines it still fixes. On Cisco's bulletins:
| Release | End of SW Maintenance Releases | End of Vulnerability/Security Support | Last Date of Support | June 2026 fixed build (CVE-2026-20245, CVE-2026-20262) |
|---|---|---|---|---|
| 20.12 | March 30, 2026 | September 30, 2027 | March 31, 2028 | 20.12.7.2 |
| 20.15 | March 30, 2027 | September 30, 2028 | March 30, 2029 | 20.15.4.5 and 20.15.5.3 |
| 20.18 | No bulletin yet | No bulletin yet | No bulletin yet | 20.18.3.1 |
| 26.1 | No bulletin yet | No bulletin yet | No bulletin yet | 26.1.1.2 |
20.12 is the cautionary row. Its End of Software Maintenance passed in March, and Cisco still shipped 20.12.7.1 in May and 20.12.7.2 in June, exactly as the bulletin language allows: after maintenance ends, security fixes continue until the security date. Its security date is a year after 20.9's. A fabric that moves from 20.9 to 20.12 buys twelve months. 20.15 buys two years. 20.18 and 26.1 have no bulletin at all, which on Cisco's cadence means the longest runway, at the cost of the newest code. Cisco's May advisory points to its Catalyst SD-WAN Upgrade Matrix for the supported path from a given 20.9 build; not every jump is direct.
What to do before the date
If you are on 20.9 and current: you have a fixed build for everything disclosed so far and security coverage until September 30, 2026. Choose the target line now and schedule the controllers first; the Manager, Controller and Validator are where the two CVSS 10.0 flaws lived, and they are what an attacker reaches from outside.
If you are on 20.9 and not current: 20.9.9.2 closes all seven exploited flaws and is the last stop on the line worth making before the migration. Cisco's advisories for CVE-2026-20128 and CVE-2026-20182 also describe indicators of compromise and, for the February flaws, a documented rebuild procedure; read them before you trust a controller that sat exposed.
If you are on 20.11, 20.13, 20.14 or 20.16: you are already where 20.9 is about to be. Cisco's tables have said "migrate to a fixed release" for those lines all year.
Everyone: the Catalyst SD-WAN page carries every release with its three Cisco milestones, and the dates on this page are bound to that data and refresh at every build. Watch 20.12's End of Software Maintenance, which has already passed, as the marker for how Cisco's bulletins behave: a line keeps getting security fixes after that date, and stops at the next one.
Frequently Asked Questions
When does Cisco Catalyst SD-WAN 20.9 reach end of support?
Cisco's end-of-life bulletin for SD-WAN Release 20.9.x sets End of Software Maintenance Releases on March 30, 2025, End of Vulnerability/Security Support on September 30, 2026 and Last Date of Support on March 30, 2027. After the security date Cisco Engineering may no longer release security fixes for 20.9; the bulletin says fixes for issues found in 20.9 may be provided through later supported releases.
Did Cisco fix the 2026 exploited SD-WAN vulnerabilities on 20.9?
Yes, all seven. Cisco's advisories list a fixed 20.9 build for each of the seven Catalyst SD-WAN entries CISA added to its Known Exploited Vulnerabilities catalog in 2026: 20.9.8.2 for CVE-2026-20127, CVE-2026-20128, CVE-2026-20122 and CVE-2026-20133; 20.9.9.1 for CVE-2026-20182; and 20.9.9.2 for CVE-2026-20245 and CVE-2026-20262. Those fixes shipped because 20.9 was still inside its End of Vulnerability/Security Support window.
Which Cisco SD-WAN release should 20.9 customers move to?
Cisco's June 2026 advisories list fixed builds for four lines besides 20.9: 20.12, 20.15, 20.18 and 26.1. On Cisco's bulletins as we serve them, 20.12's End of Vulnerability/Security Support is September 30, 2027 and 20.15's is September 30, 2028; 20.18 and 26.1 have no end-of-life bulletin yet. Check Cisco's Catalyst SD-WAN Upgrade Matrix for the supported path from your 20.9 build.
Is Cisco SD-WAN 20.9 still supported after September 30, 2026?
For technical assistance, yes, until the Last Date of Support on March 30, 2027. For security fixes, no. Cisco's bulletin language is that after the End of Vulnerability/Security Support date there will be no rebuild releases of 20.9 and fixes may be provided through later supported software releases. A 20.9 controller or manager is then in the position 20.11, 20.13, 20.14 and 20.16 already occupy in Cisco's 2026 advisories: a migrate-to-a-fixed-release row, and then no row.
Related
- Cisco Catalyst SD-WAN — every release with its End of SW Maintenance, End of Vulnerability/Security Support and Last Date of Support, from Cisco's bulletins
- Cisco FMC CVE-2026-20079 — the same lifecycle rule, seen from the other side: a train past its security date and a fix that does not name it
- EOS Edge Device List — every edge platform we track with a CISA KEV history
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to