Critical Cisco SD-WAN Vulnerability Under Active Attack
Want more insights like this?
A threat actor Cisco Talos tracks as UAT-8616 is exploiting a critical authentication bypass (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD-WAN Controller and SD-WAN Manager — formerly vSmart and vManage. Talos says exploitation has been limited so far and clusters it under UAT-8616 with high confidence. Unauthenticated attackers gain administrative access and NETCONF control over network configuration.
CISA added it to the KEV catalog the day it was disclosed and gave federal agencies until May 17 under Emergency Directive 26-03. Fixed releases are 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.12.7.1, 20.15.4.4, 20.15.5.2, 20.18.2.2 and 26.1.1.1 — check which train you're on, since older releases need migrating rather than updating. There's no workaround.
It's at least the fifth Cisco SD-WAN flaw under active exploitation this year. UAT-8616 has been exploiting a nearly identical bypass, CVE-2026-20127, since at least 2023 — Cisco called that exploitation limited, Talos called it extensive. Ten further clusters, distinct from UAT-8616, have been hitting three more SD-WAN bypasses since March, dropping webshells, cryptominers and infostealers.
UAT-8616 targets critical infrastructure and other high-value organizations globally, and reaches root by an unusual route: downgrade the software, exploit the old CVE-2022-20775, then restore the original version. Talos notes the group's infrastructure overlaps with Operational Relay Box networks it monitors. Check auth.log for "Accepted publickey for vmanage-admin" from unfamiliar IPs.
Updated August 13, 2026: Cisco patched another actively exploited SD-WAN Manager flaw in June — CVE-2026-20262, an arbitrary file write rated 6.5, KEV-listed with a June 29 federal deadline. Its fixed releases supersede the May builds: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 and 26.1.1.2. By then it was the eighth exploited Cisco SD-WAN flaw of 2026.
Source: Dark Reading