Full Report
Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.
Analysis Summary
# Vulnerability: Active Exploitation of Cisco Catalyst SD-WAN Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-20182
- **CVSS Score:** Critical (Exact score not provided in text, but categorized as high-impact authentication bypass)
- **CWE:** Authentication Bypass
*Note: The report also references active exploitation of secondary vulnerabilities CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122.*
## Affected Systems
- **Products:**
- Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
- Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
- **Versions:** Specific vulnerable versions are addressed in Cisco's security advisory (see References).
- **Configurations:** Systems exposed to the network without the latest February 2026 security updates.
## Vulnerability Description
CVE-2026-20182 is an authentication bypass vulnerability that allows a remote, unauthenticated attacker to bypass security hurdles and log into the affected system. Once exploited, the attacker can obtain administrative privileges as an internal, high-privileged, non-root user account. This provides a foothold to perform post-compromise actions such as modifying configurations or attempting further privilege escalation.
## Exploitation
- **Status:** Exploited in the wild (tracked as UAT-8616 and other threat clusters).
- **Complexity:** Low (PoC code available from ZeroZenX labs for related vulnerabilities).
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Access to administrative data and configurations)
- **Integrity:** High (Ability to modify NETCONF configurations and add SSH keys)
- **Availability:** High (Potential to disrupt SD-WAN operations via administrative access)
## Remediation
### Patches
- Cisco released software updates addressing these vulnerabilities in **February 2026**. Customers are strongly advised to upgrade to the latest fixed releases immediately.
### Workarounds
- No specific workarounds are listed; immediate patching and updating of SD-WAN infrastructure is the primary recommendation.
- Limit exposure of management interfaces to the public internet.
## Detection
### Indicators of Compromise (IoCs)
- **Malicious Tooling:** "XenShell" (JSP-based webshell), AdaptixC2, Sliver, XMRig miners, and Nim-based backdoors.
- **Threat Actor IPs:**
- 194.233.100[.]40
- 194[.]163[.]175[.]135
- 23.27.143[.]170
- 83[.]229[.]126[.]195
- 79[.]135[.]105[.]208
- 176[.]65[.]139[.]31
### Detection Methods
- Monitor for unauthorized additions of SSH keys or modifications to NETCONF configurations.
- Audit logs for logins by high-privileged internal accounts from unexpected IP addresses.
- Check for the existence of web shells (specifically JSP files) in the web directories of SD-WAN Manager.
## References
- Cisco Security Advisory (CVE-2026-20182): hxxps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- Cisco Security Advisory (Secondary CVEs): hxxps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
- Talos Intelligence Blog: hxxps://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
- Rapid7 Disclosure: hxxp://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed