SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs

In-the-Wild Exploitation of Cisco SD-WAN Flaws Leading to Unauthorized Administrative Access

Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging

May 18, 20263 min read

Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging multiple vulnerabilities to compromise SD-WAN controllers an management platforms.

These attacks reflect a growing trend in cyber operations:
targeting network orchestration layers (SD-WAN controllers and managers) to achieve centralized control over distributed network environments, enabling privilege escalation, persistence, and lateral movement.

Background on Threat Activity

Cisco Talos attributes part of this activity to a sophisticated threat cluster tracked as UAT-8616, believed to be engaged in targeted exploitation of SD-WAN environments.

Unlike opportunistic attacks, this campaign demonstrates:

  • Exploitation of authentication bypass vulnerabilities
  • Use of public proof-of-concept (PoC) exploits
  • Deployment of webshell-based persistence mechanisms
  • Post-compromise actions including:
    SSH key insertionConfiguration tamperingPrivilege escalation attempts.

Additionally, multiple unrelated threat clusters have leveraged the same vulnerabilities, indicating broad attacker interest and rapid weaponization.

Primary Targets

  • Cisco Catalyst SD-WAN Controller (vSmart)
  • Cisco Catalyst SD-WAN Manager (vManage)
  • Enterprise environments using centralized SD-WAN orchestration
  • Organizations with internet-exposed SD-WAN management interfaces

Vulnerability Details

CVE-2026-20182

  • Type: Authentication Bypass (Unauthenticated Access)
  • CVSS Score: 10.0 (Critical)
  • EPSS Score: 31.70%
  • Impact: Enables attackers to gain administrative access without credentials
  • Affected Systems: Cisco SD-WAN Controller and Manager

Tactics and Techniques

  • TA0001 – Initial Access: Authentication bypass using exposed SD-WAN interfaces
  • TA0002 – Execution: Remote command execution via webshell deployment
  • TA0003 – Persistence: Deployment of JSP-based webshells (e.g., XenShell, Godzilla, Behinder)
  • TA0005 – Defense Evasion: Use of legitimate tools and minimal artifacts
  • TA0007 – Discovery: System and network enumeration
  • TA0008 – Lateral Movement: Access expansion via compromised credentials

Indicators of Compromise (IOCs)

Network Indicators

  • 38.181.52[.]89
  • 89.125.244[.]33
  • 71.80.85[.]135
  • 212.83.162[.]37

Malware / Tooling Observed

  • XenShell (JSP webshell) – primary exploitation tool
  • Godzilla Webshell
  • Behinder Webshell
  • NimPlant (modified)
  • Sliver implant (red-team framework)
  • AdaptixC2 agent
  • XMRig cryptominer

Infection Method

Initial Access

Attackers exploited SD-WAN vulnerabilities to bypass authentication and access systems without credentials.

Exploitation

Successful exploitation allowed attackers to:

  • Gain administrative access
  • Inject and execute commands remotely
  • Modify system configurations

Payload Delivery

Attackers deployed:

  • JSP webshells (XenShell, Godzilla, Behinder)
  • Lightweight post-exploitation tools

This enabled:

  • Minimal disk footprint
  • Rapid deployment

Execution & Persistence

Persistence mechanisms included:

  • Webshell access
  • SSH key insertion
  • System configuration changes

Attackers avoided heavy malware and relied on:

  • Native tools
  • Memory-based execution

Command and Control (C2)

  • Communication via compromised SD-WAN interfaces
  • Use of external infrastructure and tunneling tools
  • Overlap with known ORB (Operational Relay Box) networks

Attack Flow

Initial Access (Auth Bypass CVEs) -> Administrative Access -> Webshell Deployment (XenShell / variants) -> Execution & Persistence -> Post-Compromise Actions (SSH keys, config changes) -> Command and Control (external infrastructure)

Mitigation Steps

  • Apply vendor patches immediately
  • Restrict access to SD-WAN management interfaces
  • Disable unnecessary external exposure

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Best Patch Management Software: Comparison and Buyer's Guide
Best Patch Management Software: Comparison and Buyer's Guide

Point of View

Best Patch Management Software: Comparison and Buyer's Guide

Compare leading patching platforms across operating system coverage, automation, third-party application support, deployment controls, reporting, and vulnerability context.

Sep 30, 2026

Open What Is Patch Management? Definition, Process, and Why It Matters
What Is Patch Management? Definition, Process, and Why It Matters

Point of View

What Is Patch Management? Definition, Process, and Why It Matters

Patch management connects software updates with asset context, risk, testing, controlled deployment, and verification. See how a structured patching process helps teams reduce unresolved software risk.

Sep 29, 2026

Open Patch Management: The Complete Guide for IT and Security Teams
Patch Management: The Complete Guide for IT and Security Teams

Point of View

Patch Management: The Complete Guide for IT and Security Teams

Sep 29, 2026

Open What Is a Software Patch? Patch vs Update Explained
What Is a Software Patch? Patch vs Update Explained

Point of View

What Is a Software Patch? Patch vs Update Explained

A software patch corrects a problem in existing software, while an update can include fixes, reliability changes, or new functionality. See how patches differ from updates and how teams manage them safely.

Sep 28, 2026