IC Technology & Surveillance — 2026-05-16

CISA Adds Cisco SD-WAN Zero-Day to Known Exploited Vulnerabilities Catalog

BLUFSequential exploitation of two authentication bypasses against identical Cisco SD-WAN components by UAT-8616, paired with ORB-linked infrastructure, points to a state intelligence operation entrenching access in carrier-grade routing fabric.

CVE-2026-20182 is a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller and Manager, allowing an unauthenticated remote attacker to gain administrative privileges via crafted packets. Cisco released patches on May 15, and CISA ordered federal civilian agencies to remediate by May 17. Cisco Talos attributed active exploitation to UAT-8616, which previously exploited CVE-2026-20127 on the same components, and reported post-compromise SSH key injection, NETCONF modification, and root escalation attempts, noting the group's infrastructure overlaps with Operational Relay Box networks. Separately, Talos documented at least 10 threat clusters exploiting three other SD-WAN CVEs since March, deploying web shells, miners, and credential stealers.

Analysis
UAT-8616's sequential exploitation of two separate authentication bypass vulnerabilities in identical Cisco SD-WAN components, followed by SSH key injection, NETCONF modification, and root escalation, indicates deliberate, sustained targeting with persistent access and configuration control objectives consistent with intelligence collection. Infrastructure overlap with Operational Relay Box networks reinforces a state intelligence mission, though Talos, the single reporting chain behind this assessment, has not attributed UAT-8616 to a specific country. The ORB connection may instead reflect commodity infrastructure leasing by a criminal or private group employing nation-state tradecraft without state tasking. Ten separate clusters exploiting three additional SD-WAN CVEs since March signals the broader attack surface has been weaponized across actors of varying sophistication.
4 sources
  1. Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 - SecurityWeek
  2. CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits - The Hacker News
  3. CISA flags new SD-WAN flaw as actively exploited in attacks - BleepingComputer
  4. Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

View in full brief →

UNCLASSIFIED // OPEN SOURCE