Cisco SD-WAN CVE-2026-20182: CVSS 10.0 Auth Bypass Actively Exploited. CISA Orders Patch by May 17.

CISA has added Cisco SD-WAN CVE-2026-20182, a CVSS 10.0 authentication bypass granting full admin access, to its KEV catalogue. Federal agencies must patch by 17 May. Cisco Talos confirms active exploitation by UAT-8616.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Cisco SD-WAN appliances in an enterprise data centre flagged for critical CVE-2026-20182 authentication bypass vulnerability added to CISA KEV catalogue

Cisco SD-WAN appliances in an enterprise data centre flagged for critical CVE-2026-20182 authentication bypass vulnerability added to CISA KEV catalogue

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalogue, requiring all Federal Civilian Executive Branch agencies to remediate the flaw no later than 17 May 2026. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0, which is the highest rating on the scale.

A flaw in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to bypass authentication entirely and gain administrative privileges on affected systems. Cisco confirmed active exploitation in limited attacks in May 2026.

Technical Exploitation and Impact

The attack works by sending specially crafted requests to the vdaemon service over DTLS on UDP port 12346. A successful exploit logs the attacker into the system as a high-privileged internal user account, from which they can access NETCONF interfaces and manipulate network configuration across the entire SD-WAN fabric.

Cisco Talos has attributed active exploitation with high confidence to a threat cluster designated UAT-8616, the same group behind the weaponisation of CVE-2026-20127, a related authentication bypass affecting the same vdaemon service. Post-compromise behaviour by UAT-8616 following exploitation of CVE-2026-20182 mirrors earlier campaigns, including SSH key additions, NETCONF configuration tampering, and root privilege escalation. The infrastructure used by UAT-8616 overlaps with Operational Relay Box (ORB) networks.

Broader Threat Landscape

At least ten distinct threat clusters have been observed exploiting three related SD-WAN vulnerabilities since March 2026: CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122. These were added to the CISA KEV catalogue last month. When chained, these three flaws allow a remote unauthenticated attacker to gain unauthorised device access without user interaction.

The current wave of exploitation is leveraging publicly available proof-of-concept exploit code to deploy web shells on compromised systems. Shells observed include Godzilla, Behinder, and XenShell. At least one cluster is deploying an XMRig cryptominer, while another is running a credential stealer targeting admin hashdumps, JWT key chunks for REST API authentication, and AWS credentials from vManage.

Regional Relevance and Affected Systems

The vulnerability affects on-premises Cisco SD-WAN deployments, Cisco SD-WAN Cloud-Pro, Cisco-Managed SD-WAN Cloud, and Cisco SD-WAN for Government under FedRAMP. For enterprises and government agencies across the GCC, where Cisco SD-WAN is widely deployed across telecommunications, financial services, and public sector networks, the attack surface is directly relevant.

The UAE Cyber Security Council and Saudi Arabia's National Cybersecurity Authority have both previously issued guidance urging organisations to maintain current patch levels on network infrastructure. The UAE Cyber Factory, launched this week specifically to counter the scale of daily attacks on national digital infrastructure, has identified unpatched network perimeter devices as a primary entry vector.

Discovery and Remediation

Rapid7, which discovered CVE-2026-20182 independently alongside researchers Jonah Burgess and Stephen Fewer, confirmed the flaw is distinct from CVE-2026-20127 and not a patch bypass. The end result, however, is identical: a remote unauthenticated attacker becomes an authenticated peer of the target appliance with full access to privileged operations.

Cisco is advising all customers to audit /var/log/auth.log for entries referencing "Accepted publickey for vmanage-admin" from unrecognised IP addresses. Suspicious peering events, particularly unauthorised peer connections at unexpected times from unrecognised sources, are also indicators of compromise that warrant immediate investigation. Patches are available now. Any organisation that has not yet applied updates should do so immediately and treat any internet-exposed SD-WAN Controller or Manager ports as potentially compromised until a full log audit is completed.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Network Security VulnerabilitiesCISA Known Exploited VulnerabilitiesCISA Known Exploited VulnerabilitiesSD-WAN SecurityThreat Intelligence MENA