CISA Adds Critical Cisco SD-WAN Vulnerability to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20182, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, to its Known Exploited Vulnerabilities (KEV) catalog. Rated 10.0 on the CVSS scale, this flaw allows unauthenticated remote attackers to gain administrative privileges. Federal Civilian Executive Branch agencies are mandated to remediate the issue by May 17, 2026. Cisco attributes active exploitation with high confidence to threat cluster UAT-8616, which employs similar post-compromise tactics as seen in previous attacks, including adding SSH keys and escalating privileges. The infrastructure overlaps with Operational Relay Box networks. Additionally, at least ten distinct threat clusters have been observed exploiting related vulnerabilities since March 2026, deploying various malware such as Godzilla, Behinder, and XenShell web shells, cryptocurrency miners, and credential stealers. These actors leverage publicly available proof-of-concept code to compromise systems. Cisco urges customers to apply recommended security patches immediately to protect their environments from these widespread and severe threats targeting SD-WAN infrastructure.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection