Cisco disclosed and patched CVE-2026-20182, a critical CVSS 10.0 authentication bypass flaw in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager that has been exploited in the wild. The bug affects the vdaemon control-plane service over DTLS/UDP 12346 and allows an unauthenticated attacker to impersonate a trusted peer, gain high-privilege administrative access, reach NETCONF on TCP/830, and manipulate SD-WAN fabric configuration. Rapid7 said the flaw stems from missing authentication checks when a peer claims to be a vHub device, enabling attackers to inject SSH keys for the vmanage-admin account and establish persistent access; Cisco said there are no workarounds and released fixed software versions for affected on-premises, cloud, managed-cloud, and FedRAMP deployments.
Cisco Talos attributed the most sophisticated exploitation of CVE-2026-20182 with high confidence to UAT-8616, which was observed adding SSH keys, modifying NETCONF settings, and escalating privileges to root, with infrastructure overlap noted with Operational Relay Box networks. Talos also reported broader ongoing attacks against SD-WAN environments, including widespread exploitation of previously disclosed CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 after public proof-of-concept release, leading to deployment of JSP webshells such as XenShell, Godzilla, and Behinder, along with tools including Sliver, AdaptixC2, XMRig, gsocket, and credential-stealing scripts. CISA added CVE-2026-20182 to the KEV catalog and ordered federal agencies to remediate quickly, while Cisco and national cyber agencies urged organizations to preserve forensic evidence, review logs for unauthorized peering and vmanage-admin public-key logins, and patch all vulnerable control components immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Cisco published detailed remediation guidance instructing customers to collect admin-tech files from all control components before upgrading, then upgrade all vulnerable systems and open a TAC case for indicator scanning. The guidance also included manual verification steps and clarified that Cisco-hosted SD-WAN Cloud customers were already upgraded or scheduled for upgrades.
A ProjectDiscovery nuclei-templates pull request for CVE-2026-20182 was opened, showing public detection content was being prepared for the flaw. The visible content reflects repository workflow activity rather than exploit details.
The Canadian Centre for Cyber Security issued an alert warning of active exploitation of CVE-2026-20182. It highlighted incidents involving added SSH keys, modified NETCONF configurations, and escalation to root privileges.
CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. The KEV entry set a federal remediation due date of May 17, 2026.
Cisco Talos reported active in-the-wild exploitation of CVE-2026-20182 and attributed the activity to the sophisticated cluster UAT-8616. Talos said the actor attempted post-compromise actions including adding SSH keys, modifying NETCONF configurations, and escalating privileges to root.
Rapid7 disclosed that CVE-2026-20182 stems from missing authentication logic in the vdaemon service when a peer claims device type 2 (vHub). It showed attackers could become authenticated control-plane peers and append an SSH key to the vmanage-admin account for persistent NETCONF access.
Cisco published security advisories and released fixed software for CVE-2026-20182, a critical authentication bypass affecting Cisco Catalyst SD-WAN Controller and Manager. Cisco said there are no workarounds and warned the flaw had been exploited in limited attacks.
Cisco said it observed limited active exploitation of CVE-2026-20182 in May 2026, indicating the flaw was used as a zero-day before public disclosure. Reporting described attacks gaining high-privileged administrative access on SD-WAN systems.
Cisco Talos observed widespread exploitation from March to April 2026 of CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 after ZeroZenX Labs released public proof-of-concept code. Multiple threat clusters used the flaws to deploy JSP webshells and additional tooling.
Cisco had released fixes and advisories in February 2026 for Cisco SD-WAN Manager vulnerabilities CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. Later reporting said these flaws were subsequently exploited in the wild.
Rapid7's disclosure timeline says coordinated reporting to Cisco for CVE-2026-20182 began on March 9, 2026. The vulnerability was discovered by Stephen Fewer and Jonah Burgess during research into related Cisco SD-WAN issues.
Cisco warned that two additional Cisco Catalyst SD-WAN Manager vulnerabilities, CVE-2026-20122 and CVE-2026-20128, were being actively exploited. The warning expanded the list of SD-WAN flaws known to be abused in the wild.
CISA and partner agencies released guidance about ongoing global exploitation of Cisco SD-WAN systems tied to earlier campaigns against the platform. This established the broader incident context that later reporting linked to UAT-8616 activity against Cisco SD-WAN infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
47 references tracked. Mallory keeps watching after this page renders.
cisco.com
Open sourceccb.belgium.be
Open sourceresecurity.com
Open sourcescworld.com
Open sourcecybersecuritydive.com
Open sourcecert.ssi.gouv.fr
Open sourcecisco.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.