CISA Adds Cisco SD-WAN Zero-Day to Known Exploited Vulnerabilities Catalog
CVE-2026-20182 is a CVSS 10.0 authentication bypass in
UAT-8616's sequential exploitation of two separate authentication bypass vulnerabilities in identical Cisco SD-WAN components, followed by SSH key injection, NETCONF modification, and root escalation, indicates deliberate, sustained targeting with persistent access and configuration control objectives consistent with intelligence collection. Infrastructure overlap with Operational Relay Box networks reinforces a state intelligence mission, though Talos, the single reporting chain behind this assessment, has not attributed UAT-8616 to a specific country. The ORB connection may instead reflect commodity infrastructure leasing by a criminal or private group employing nation-state tradecraft without state tasking. Ten separate clusters exploiting three additional SD-WAN CVEs since March signals the broader attack surface has been weaponized across actors of varying sophistication.
4 sources
- Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 -
SecurityWeek - CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits -
The Hacker News - CISA flags new SD-WAN flaw as actively exploited in attacks -
BleepingComputer - Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability