SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs

In-the-Wild Exploitation of Cisco SD-WAN Flaws Leading to Unauthorized Administrative Access

Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging

May 18, 20263 min read

Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging multiple vulnerabilities to compromise SD-WAN controllers an management platforms.

These attacks reflect a growing trend in cyber operations:
targeting network orchestration layers (SD-WAN controllers and managers) to achieve centralized control over distributed network environments, enabling privilege escalation, persistence, and lateral movement.

Background on Threat Activity

Cisco Talos attributes part of this activity to a sophisticated threat cluster tracked as UAT-8616, believed to be engaged in targeted exploitation of SD-WAN environments.

Unlike opportunistic attacks, this campaign demonstrates:

  • Exploitation of authentication bypass vulnerabilities
  • Use of public proof-of-concept (PoC) exploits
  • Deployment of webshell-based persistence mechanisms
  • Post-compromise actions including:
    SSH key insertionConfiguration tamperingPrivilege escalation attempts.

Additionally, multiple unrelated threat clusters have leveraged the same vulnerabilities, indicating broad attacker interest and rapid weaponization.

Primary Targets

  • Cisco Catalyst SD-WAN Controller (vSmart)
  • Cisco Catalyst SD-WAN Manager (vManage)
  • Enterprise environments using centralized SD-WAN orchestration
  • Organizations with internet-exposed SD-WAN management interfaces

Vulnerability Details

CVE-2026-20182

  • Type: Authentication Bypass (Unauthenticated Access)
  • CVSS Score: 10.0 (Critical)
  • EPSS Score: 31.70%
  • Impact: Enables attackers to gain administrative access without credentials
  • Affected Systems: Cisco SD-WAN Controller and Manager

Tactics and Techniques

  • TA0001 – Initial Access: Authentication bypass using exposed SD-WAN interfaces
  • TA0002 – Execution: Remote command execution via webshell deployment
  • TA0003 – Persistence: Deployment of JSP-based webshells (e.g., XenShell, Godzilla, Behinder)
  • TA0005 – Defense Evasion: Use of legitimate tools and minimal artifacts
  • TA0007 – Discovery: System and network enumeration
  • TA0008 – Lateral Movement: Access expansion via compromised credentials

Indicators of Compromise (IOCs)

Network Indicators

  • 38.181.52[.]89
  • 89.125.244[.]33
  • 71.80.85[.]135
  • 212.83.162[.]37

Malware / Tooling Observed

  • XenShell (JSP webshell) – primary exploitation tool
  • Godzilla Webshell
  • Behinder Webshell
  • NimPlant (modified)
  • Sliver implant (red-team framework)
  • AdaptixC2 agent
  • XMRig cryptominer

Infection Method

Initial Access

Attackers exploited SD-WAN vulnerabilities to bypass authentication and access systems without credentials.

Exploitation

Successful exploitation allowed attackers to:

  • Gain administrative access
  • Inject and execute commands remotely
  • Modify system configurations

Payload Delivery

Attackers deployed:

  • JSP webshells (XenShell, Godzilla, Behinder)
  • Lightweight post-exploitation tools

This enabled:

  • Minimal disk footprint
  • Rapid deployment

Execution & Persistence

Persistence mechanisms included:

  • Webshell access
  • SSH key insertion
  • System configuration changes

Attackers avoided heavy malware and relied on:

  • Native tools
  • Memory-based execution

Command and Control (C2)

  • Communication via compromised SD-WAN interfaces
  • Use of external infrastructure and tunneling tools
  • Overlap with known ORB (Operational Relay Box) networks

Attack Flow

Initial Access (Auth Bypass CVEs) -> Administrative Access -> Webshell Deployment (XenShell / variants) -> Execution & Persistence -> Post-Compromise Actions (SSH keys, config changes) -> Command and Control (external infrastructure)

Mitigation Steps

  • Apply vendor patches immediately
  • Restrict access to SD-WAN management interfaces
  • Disable unnecessary external exposure

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open What happens after AI finds a vulnerability?

What happens after AI finds a vulnerability?

Point of View

What happens after AI finds a vulnerability?

AI can find vulnerabilities faster, but what happens next? Part 1 of a 3-part series on the impact of Mythos on enterprise security.

Sep 17, 2026

Open This Tiny Linux Flaw Could Give Hackers Total Control: Meet ‘Copy Fail’

This Tiny Linux Flaw Could Give Hackers Total Control: Meet ‘Copy Fail’

Point of View

This Tiny Linux Flaw Could Give Hackers Total Control: Meet ‘Copy Fail’

The cybersecurity landscape is once again facing a critical threat as active exploitation of the “Copy Fail” Linux kernel vulnerability has been detected in the wild. This vulnerability, tracked as CVE-2026-31431, allows unprivileged local users to gain root privileges on vulnerable systems, posing

Sep 17, 2026

Open The cPanel Crisis: One Bug, Millions Exposed as Mirai and ‘Sorry’ Ransomware Deploy in 24 Hours

The cPanel Crisis: One Bug, Millions Exposed as Mirai and ‘Sorry’ Ransomware Deploy in 24 Hours

Point of View

The cPanel Crisis: One Bug, Millions Exposed as Mirai and ‘Sorry’ Ransomware Deploy in 24 Hours

Researchers have uncovered active exploitation of a critical vulnerability in cPanel & WHM (CVE-2026-41940), an authentication bypass flaw that has been abused as a zero-day following public disclosure. The vulnerability was rapidly weaponized within 24 hours, with multiple third parties leveraging

Sep 17, 2026

Open ShadowPad Rising: SHADOW-EARTH-053 Hits Exchange Servers

ShadowPad Rising: SHADOW-EARTH-053 Hits Exchange Servers

Point of View

ShadowPad Rising: SHADOW-EARTH-053 Hits Exchange Servers

Executive Summary A cyber espionage campaign attributed to the China-linked threat cluster SHADOW-EARTH-053 has been observed targeting government, defense, telecommunications, and transportation organizations across South, East, and Southeast Asia, as well as a European NATO member state. The attac

Sep 17, 2026