CVE-2026-20182: Cisco SD-WAN Authentication Bypass Exploited by Nation-State Actor UAT-8616
How nation-state threat group UAT-8616 weaponized a Cisco SD-WAN authentication bypass to compromise enterprise transit hubs.
CVE-2026-20182
Severity: CVSS 9.8
Status: ⚠️ Nation-State In-The-Wild Exploitation (UAT-8616)
Target Component: Cisco Catalyst SD-WAN
CVE-2026-20182 is a CVSS 10.0 critical authentication bypass in Cisco Catalyst SD-WAN Controller that allows an unauthenticated, remote attacker to gain administrative privileges. CISA added it to the Known Exploited Vulnerabilities catalog on May 14, 2026, and Cisco Talos attributes active exploitation to UAT-8616.
Vulnerability Details
- CVE: CVE-2026-20182
- CVSS v3.1: 10.0 (Critical)
- Affected products: Cisco Catalyst SD-WAN Controller (formerly vSmart), Cisco Catalyst SD-WAN Manager (formerly vManage)
- Attack vector: Network (remote, unauthenticated)
- CWE: CWE-287 (Improper Authentication)
Technical Root Cause
The vulnerability resides in the vdaemon service, which communicates over DTLS on UDP port 12346. When a connecting peer claims to be a vHub device type, a device-type-specific certificate verification step is skipped. However, the code path continues and marks the peer as authenticated despite not completing verification — granting the attacker the equivalent of an internal high-privileged non-root user account.
Once authenticated via this path, the attacker can access NETCONF interfaces, append SSH public keys to /home/vmanage-admin/.ssh/authorized_keys for persistence, escalate to root via a secondary local privilege escalation, and pivot to all managed SD-WAN edge devices.
UAT-8616 Exploitation
Cisco Talos clusters the active exploitation under UAT-8616, a highly sophisticated threat actor who previously exploited the related CVE-2026-20127. Post-exploitation activities include adding SSH public keys for persistent access, modifying NETCONF configurations to reroute SD-WAN traffic, root privilege escalation attempts via kernel exploits, and lateral movement to managed edge routers. UAT-8616's pattern is consistent with nation-state reconnaissance and traffic interception objectives.
Affected Versions and Patches
Patches are available. Upgrade immediately to:
- Cisco Catalyst SD-WAN Controller 20.12.4 or later
- Cisco Catalyst SD-WAN Manager 20.12.4 or later
Cisco's full advisory: cisco-sa-sdwan-rpa2-v69WY2SW.
What to Do
Patch immediately: Upgrade SD-WAN Controller and Manager to 20.12.4+. No acceptable delay given CVSS 10.0 and active exploitation.
Restrict UDP/12346: If patching must be deferred, restrict the vdaemon DTLS port to known, trusted IP ranges via ACLs.
Audit SSH authorized_keys:
cat /home/vmanage-admin/.ssh/authorized_keys
# Compare against known-good baselineReview NETCONF configuration history: Pull NETCONF audit logs and compare current configuration against a known-good backup to identify unauthorized changes.
Hunt for UAT-8616 IOCs: Review SD-WAN logs for connection attempts to the vdaemon port from unexpected IPs, particularly 185.x.x.x and 91.x.x.x ranges associated with prior UAT-8616 infrastructure.
→ Back to the Week of May 21 Security Roundup