CVE-2026-20182 is a maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller and Manager requiring no credentials or user interaction, actively exploited by a China-nexus threat actor. Every deployment type, including FedRAMP-authorized government environments, is affected. Patching does not remediate already-compromised systems; forensic validation is required for any previously internet-exposed deployment.