Campaigns
CRITICAL Cisco Catalyst SD-WAN AUTHENTICATION BYPASS CVE-2026-20182 Exploitation Campaign

CRITICAL Cisco Catalyst SD-WAN AUTHENTICATION BYPASS CVE-2026-20182 Exploitation Campaign

CVE-2026-20182CVE-2026-20127CVE-2022-20775CVE-2026-20133CVE-2026-20122Cisco Catalyst SD-WANvSmartvManageAuthentication BypassPeering AuthenticationvdaemonDTLSNETCONFvmanage-adminSSH Key InjectionUAT-8616ORB NetworkOperational Relay BoxXenShellGodzilla WebshelZeroZenX LabsEmergency Directive 26-03Critical Infrastructure Targeting
A highly sophisticated threat actor tracked by Cisco Talos as UAT 8616 active against Cisco SD-WAN infrastructure since at least 2023 and operating from Operational Relay Box (ORB) networks — has been observed exploiting CVE-2026-20182, a critical (CVSS 10.0) authentication bypass in Cisco Catalyst SD-WAN Controller (vSmart) and Manager (vManage) via the vdaemon DTLS peering service on UDP/12346.

Indicators of Compromise

image.update-kaspersky.workers.dev
msiidentity.com
update-kaspersky.workers.dev
trafficmanagerupdate.com
www.drivelivelime.com

APT Groups1

UAT-8616null

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION
REF


Technique ID

Technique Name

Tactic

Detection Method

Log Sources

T1190

Exploit Public-Facing Application

Initial Access

Inspect /var/log/auth.log and SD-WAN Controller audit logs for `Accepted publickey for vmanage-admin` entries originating from unknown or unauthorised IP addresses; cross-reference against authorised peer inventories and administrative jump-host ranges.

/var/log/auth.log (SD-WAN Controller), Cisco Catalyst SD-WAN audit logs, SIEM correlation

T1190

Exploit Public-Facing Application

Initial Access

Run `show control connections detail` and `show control connections-history detail`; flag peer entries with state:up combined with challenge-ack:0, peers claiming device type 2 (vHub) where no vHub is deployed, and peering events outside of documented maintenance windows.

Cisco Catalyst SD-WAN show-commands, admin-tech bundle, vdebug logs

T1098.004

Account Manipulation: SSH Authorized Keys

Persistence

Continuous integrity monitoring of /home/vmanage-admin/.ssh/authorized_keys and /home/root/.ssh/authorized_keys; alert on any addition, modification, or deletion.

auditd (path watches), Sysmon for Linux EID 11, EDR file-integrity telemetry

T1078

Valid Accounts

Initial Access

Audit Cisco Catalyst SD-WAN Manager for unexpected administrative users; review the system-login-change notifications (e.g. `Notification: system-login-change ... user-name:"root"`) for unaccounted interactive root sessions on production systems.

vManage user audit, vsyslog, syslog, SD-WAN notification stream

T1543

Create or Modify System Process

Persistence

Inspect /etc/ssh/sshd_config for PermitRootLogin transitioning from no to yes; alert on any sshd configuration change on Controller or Manager appliances.

auditd (file-watch on /etc/ssh/sshd_config), configuration management telemetry

T1574

Hijack Execution Flow (Software Downgrade)

Privilege Escalation / Defense Evasion

Alert on unexpected SD-WAN appliance reboots followed by detectable version changes; correlate with downgrade-and-restore patterns characteristic of UAT-8616's CVE-2022-20775 abuse.

Cisco Catalyst SD-WAN upgrade logs, admin-tech version history, change-management records

T1070

Indicator Removal on Host

Defense Evasion

Detect missing or unexpectedly truncated bash_history, cli-history, vsyslog and vdebug entries on control components; correlate gaps with prior administrative-session telemetry.

Remote SIEM ingestion of vsyslog/vdebug, bash_history shipping, EDR forensic snapshots

T1090.003

Proxy: Multi-hop Proxy

Command and Control

Hunt for outbound connections from SD-WAN control components to ORB-class infrastructure; flag long-lived sessions with consistent jitter and low-reputation destinations.

NetFlow / IPFIX, TLS metadata (JA3/JA4), egress proxy / NGFW logs

T1505.003

Server Software Component: Web Shell (related cluster)

Persistence

For the parallel CVE-2026-20133 / -20128 / -20122 chain on unpatched vManage, hunt for the JSP-based XenShell (ZeroZenX Labs PoC derivative) and the Godzilla webshell; inspect web-root directories for unexpected .jsp files.

vManage web-server logs, file-integrity monitoring on web roots, WAF / reverse-proxy logs

Observed Countries250

AD (268)
AE (557)
AF (7)
AG (807)
AI (508)
AL (601)
AM (35)
AO (667)
AQ (954)
AR (105)
AS (67)
AT (539)
AU (682)
AW (774)
AX (988)
AZ (800)
BA (812)
BB (71)
BD (21)
BE (125)
BF (409)
BG (771)
BH (925)
BI (390)
BJ (708)
BL (129)
BM (8)
BN (20)
BO (760)
BQ (793)
BR (811)
BS (697)
BT (36)
BV (236)
BW (703)
BY (351)
BZ (671)
CA (810)
CC (577)
CD (312)
CF (976)
CG (785)
CH (772)
CI (812)
CK (377)
CL (839)
CM (724)
CN (81)
CO (784)
CR (358)
CU (550)
CV (381)
CW (834)
CX (547)
CY (33)
CZ (621)
DE (170)
DJ (592)
DK (839)
DM (686)
DO (139)
DZ (922)
EC (456)
EE (352)
EG (94)
EH (549)
ER (644)
ES (990)
ET (483)
FI (466)
FJ (766)
FK (313)
FM (594)
FO (316)
FR (651)
GA (107)
GB (382)
GD (265)
GE (449)
GF (554)
GG (600)
GH (566)
GI (314)
GL (770)
GM (854)
GN (179)
GP (278)
GQ (239)
GR (252)
GS (182)
GT (123)
GU (450)
GW (445)
GY (377)
HK (397)
HM (6)
HN (735)
HR (112)
HT (254)
HU (82)
ID (742)
IE (815)
IL (311)
IM (288)
IN (42)
IO (364)
IQ (390)
IR (897)
IS (581)
IT (14)
JE (294)
JM (638)
JO (971)
JP (147)
KE (948)
KG (668)
KH (223)
KI (3)
KM (432)
KN (125)
KP (945)
KR (189)
KW (282)
KY (834)
KZ (181)
LA (450)
LB (765)
LC (745)
LI (770)
LK (69)
LR (747)
LS (487)
LT (792)
LU (635)
LV (636)
LY (122)
MA (952)
MC (892)
MD (964)
ME (697)
MF (962)
MG (11)
MH (489)
MK (454)
ML (229)
MM (633)
MN (810)
MO (182)
MP (245)
MQ (971)
MR (32)
MS (280)
MT (434)
MU (951)
MV (689)
MW (583)
MX (252)
MY (275)
MZ (397)
NA (705)
NC (684)
NE (495)
NF (832)
NG (929)
NI (902)
NL (705)
NO (944)
NP (586)
NR (312)
NU (552)
NZ (979)
OM (633)
PA (775)
PE (215)
PF (371)
PG (38)
PH (830)
PK (483)
PL (264)
PM (974)
PN (969)
PR (367)
PS (319)
PT (907)
PW (348)
PY (449)
QA (241)
RE (350)
RO (656)
RS (687)
RU (865)
RW (405)
SA (9)
SB (494)
SC (340)
SD (603)
SE (181)
SG (890)
SH (66)
SI (355)
SJ (333)
SK (505)
SL (63)
SM (32)
SN (416)
SO (181)
SR (493)
SS (619)
ST (125)
SV (827)
SX (270)
SY (73)
SZ (319)
TC (593)
TD (842)
TF (867)
TG (390)
TH (810)
TJ (48)
TK (846)
TL (534)
TM (157)
TN (133)
TO (431)
TR (282)
TT (158)
TV (959)
TW (141)
TZ (475)
UA (999)
UG (86)
UM (515)
US (61)
UY (842)
UZ (831)
VA (766)
VC (880)
VE (479)
VG (754)
VI (616)
VN (975)
VU (58)
WF (660)
WS (648)
XK (82)
YE (343)
YT (120)
ZA (882)
ZM (440)
ZW (367)