Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogperimeter-device-exposurewidely-deployed-product-advisory

Cisco SD-WAN Authentication Bypass Exploited for Admin Access and Persistence

Updated 6d agoFirst seen May 14, 202645 sources

Cisco disclosed and patched CVE-2026-20182, a critical CVSS 10.0 authentication bypass flaw in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager that has been exploited in the wild. The bug affects the vdaemon control-plane service over DTLS/UDP 12346 and allows an unauthenticated attacker to impersonate a trusted peer, gain high-privilege administrative access, reach NETCONF on TCP/830, and manipulate SD-WAN fabric configuration. Rapid7 said the flaw stems from missing authentication checks when a peer claims to be a vHub device, enabling attackers to inject SSH keys for the vmanage-admin account and establish persistent access; Cisco said there are no workarounds and released fixed software versions for affected on-premises, cloud, managed-cloud, and FedRAMP deployments.

Cisco Talos attributed the most sophisticated exploitation of CVE-2026-20182 with high confidence to UAT-8616, which was observed adding SSH keys, modifying NETCONF settings, and escalating privileges to root, with infrastructure overlap noted with Operational Relay Box networks. Talos also reported broader ongoing attacks against SD-WAN environments, including widespread exploitation of previously disclosed CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 after public proof-of-concept release, leading to deployment of JSP webshells such as XenShell, Godzilla, and Behinder, along with tools including Sliver, AdaptixC2, XMRig, gsocket, and credential-stealing scripts. CISA added CVE-2026-20182 to the KEV catalog and ordered federal agencies to remediate quickly, while Cisco and national cyber agencies urged organizations to preserve forensic evidence, review logs for unauthorized peering and vmanage-admin public-key logins, and patch all vulnerable control components immediately.

Share:
Cisco SD-WAN Authentication Bypass Exploited for Admin Access and Persistence
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
May 18, 202627d ago

Cisco publishes remediation workflow for May SD-WAN advisories

Cisco published detailed remediation guidance instructing customers to collect admin-tech files from all control components before upgrading, then upgrade all vulnerable systems and open a TAC case for indicator scanning. The guidance also included manual verification steps and clarified that Cisco-hosted SD-WAN Cloud customers were already upgraded or scheduled for upgrades.

Remediate Catalyst SD-WAN Security Advisory - May 2026 - Cisco
May 15, 20261mo ago

Nuclei template pull request appears for CVE-2026-20182 detection

A ProjectDiscovery nuclei-templates pull request for CVE-2026-20182 was opened, showing public detection content was being prepared for the flaw. The visible content reflects repository workflow activity rather than exploit details.

CVE-2026-20182 - Cisco Catalyst SD-WAN Controller - vHub Authentication Bypass by DhiyaneshGeek · Pull Request #16179 · projectdiscovery/nuclei-templates · GitHub

Canadian Centre for Cyber Security issues alert on CVE-2026-20182

The Canadian Centre for Cyber Security issued an alert warning of active exploitation of CVE-2026-20182. It highlighted incidents involving added SSH keys, modified NETCONF configurations, and escalation to root privileges.

AL26-012 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20182 - Canadian Centre for Cyber Security
May 14, 20261mo ago

CISA adds CVE-2026-20182 to the KEV catalog

CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. The KEV entry set a federal remediation due date of May 17, 2026.

Add Updated KEV Files for 2026-05-14 · cisagov/kev-data@8cac279 · GitHub

Talos attributes CVE-2026-20182 exploitation to UAT-8616

Cisco Talos reported active in-the-wild exploitation of CVE-2026-20182 and attributed the activity to the sophisticated cluster UAT-8616. Talos said the actor attempted post-compromise actions including adding SSH keys, modifying NETCONF configurations, and escalating privileges to root.

Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

Rapid7 publicly discloses technical details of CVE-2026-20182

Rapid7 disclosed that CVE-2026-20182 stems from missing authentication logic in the vdaemon service when a peer claims device type 2 (vHub). It showed attackers could become authenticated control-plane peers and append an SSH key to the vmanage-admin account for persistent NETCONF access.

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

Cisco discloses and patches CVE-2026-20182

Cisco published security advisories and released fixed software for CVE-2026-20182, a critical authentication bypass affecting Cisco Catalyst SD-WAN Controller and Manager. Cisco said there are no workarounds and warned the flaw had been exploited in limited attacks.

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco observes limited exploitation of CVE-2026-20182 in May

Cisco said it observed limited active exploitation of CVE-2026-20182 in May 2026, indicating the flaw was used as a zero-day before public disclosure. Reporting described attacks gaining high-privileged administrative access on SD-WAN systems.

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Public PoC release triggers broader exploitation of older SD-WAN flaws

Cisco Talos observed widespread exploitation from March to April 2026 of CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 after ZeroZenX Labs released public proof-of-concept code. Multiple threat clusters used the flaws to deploy JSP webshells and additional tooling.

Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

Cisco fixes and discloses earlier SD-WAN flaws later abused in campaigns

Cisco had released fixes and advisories in February 2026 for Cisco SD-WAN Manager vulnerabilities CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. Later reporting said these flaws were subsequently exploited in the wild.

Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
Mar 9, 20263mo ago

Rapid7 begins coordinated reporting of CVE-2026-20182 to Cisco

Rapid7's disclosure timeline says coordinated reporting to Cisco for CVE-2026-20182 began on March 9, 2026. The vulnerability was discovered by Stephen Fewer and Jonah Burgess during research into related Cisco SD-WAN issues.

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
Mar 6, 20263mo ago

Cisco warns CVE-2026-20122 and CVE-2026-20128 are under active exploitation

Cisco warned that two additional Cisco Catalyst SD-WAN Manager vulnerabilities, CVE-2026-20122 and CVE-2026-20128, were being actively exploited. The warning expanded the list of SD-WAN flaws known to be abused in the wild.

Cisco warns of two more SD-WAN bugs under active attack
Feb 25, 20264mo ago

Cisco and partners release guidance on ongoing SD-WAN exploitation

CISA and partner agencies released guidance about ongoing global exploitation of Cisco SD-WAN systems tied to earlier campaigns against the platform. This established the broader incident context that later reporting linked to UAT-8616 activity against Cisco SD-WAN infrastructure.

CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems | CISA
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

64 LINKEDOpen in app
Threat actors
1 linked
Affected products
14 linked
ZoomMetasploitOpensslInsightvmNexposeMetasploit FrameworkSimplehelpScreenconnectAmazon Web ServicesSd-Wan Vsmart Controller SoftwareSd-Wan Vedge RoutersSd-Wan Vedge Cloud RoutersSd-Wan Vmanage SoftwareSd-Wan Vbond Orchestrator Software
Organizations
26 linked
Cisco SystemsRapid7Zoom CommunicationsMicrosoft CorporationZeroZenX LabsSecurityScorecardAnthropicDriftnetKeeper SecurityReplitBeyondtrustTenableDark ReadingOpenaiBeazley SecurityConnectwiseGitHubSimpleHelpProtonCyberScoopContaboGoogleSecurity AffairsThe Hacker NewsBerriAIHadrian
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cisco SD-WAN Authentication Bypass Exploited for Admin Access and Persistence | Mallory