CVE-2026-20182: Cisco SD-WAN Authentication Bypass Exploited by Nation-State Actor UAT-8616

How nation-state threat group UAT-8616 weaponized a Cisco SD-WAN authentication bypass to compromise enterprise transit hubs.

CVE-2026-20182: Cisco SD-WAN Authentication Bypass Exploited by Nation-State Actor UAT-8616
📌
Security Roundup Series: Week of May 21, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-20182 Severity: CVSS 9.8 Status: ⚠️ Nation-State In-The-Wild Exploitation (UAT-8616) Target Component: Cisco Catalyst SD-WAN

CVE-2026-20182 is a CVSS 10.0 critical authentication bypass in Cisco Catalyst SD-WAN Controller that allows an unauthenticated, remote attacker to gain administrative privileges. CISA added it to the Known Exploited Vulnerabilities catalog on May 14, 2026, and Cisco Talos attributes active exploitation to UAT-8616.


Vulnerability Details

  • CVE: CVE-2026-20182
  • CVSS v3.1: 10.0 (Critical)
  • Affected products: Cisco Catalyst SD-WAN Controller (formerly vSmart), Cisco Catalyst SD-WAN Manager (formerly vManage)
  • Attack vector: Network (remote, unauthenticated)
  • CWE: CWE-287 (Improper Authentication)

Technical Root Cause

The vulnerability resides in the vdaemon service, which communicates over DTLS on UDP port 12346. When a connecting peer claims to be a vHub device type, a device-type-specific certificate verification step is skipped. However, the code path continues and marks the peer as authenticated despite not completing verification — granting the attacker the equivalent of an internal high-privileged non-root user account.

Once authenticated via this path, the attacker can access NETCONF interfaces, append SSH public keys to /home/vmanage-admin/.ssh/authorized_keys for persistence, escalate to root via a secondary local privilege escalation, and pivot to all managed SD-WAN edge devices.


UAT-8616 Exploitation

Cisco Talos clusters the active exploitation under UAT-8616, a highly sophisticated threat actor who previously exploited the related CVE-2026-20127. Post-exploitation activities include adding SSH public keys for persistent access, modifying NETCONF configurations to reroute SD-WAN traffic, root privilege escalation attempts via kernel exploits, and lateral movement to managed edge routers. UAT-8616's pattern is consistent with nation-state reconnaissance and traffic interception objectives.


Affected Versions and Patches

Patches are available. Upgrade immediately to:

  • Cisco Catalyst SD-WAN Controller 20.12.4 or later
  • Cisco Catalyst SD-WAN Manager 20.12.4 or later

Cisco's full advisory: cisco-sa-sdwan-rpa2-v69WY2SW.


What to Do

Patch immediately: Upgrade SD-WAN Controller and Manager to 20.12.4+. No acceptable delay given CVSS 10.0 and active exploitation.

Restrict UDP/12346: If patching must be deferred, restrict the vdaemon DTLS port to known, trusted IP ranges via ACLs.

Audit SSH authorized_keys:

cat /home/vmanage-admin/.ssh/authorized_keys
# Compare against known-good baseline

Review NETCONF configuration history: Pull NETCONF audit logs and compare current configuration against a known-good backup to identify unauthorized changes.

Hunt for UAT-8616 IOCs: Review SD-WAN logs for connection attempts to the vdaemon port from unexpected IPs, particularly 185.x.x.x and 91.x.x.x ranges associated with prior UAT-8616 infrastructure.

→ Back to the Week of May 21 Security Roundup


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther