In-the-Wild Exploitation of Cisco SD-WAN Flaws Leading to Unauthorized Administrative Access
Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging
Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging multiple vulnerabilities to compromise SD-WAN controllers an management platforms.
These attacks reflect a growing trend in cyber operations:
targeting network orchestration layers (SD-WAN controllers and managers) to achieve centralized control over distributed network environments, enabling privilege escalation, persistence, and lateral movement.
Background on Threat Activity
Cisco Talos attributes part of this activity to a sophisticated threat cluster tracked as UAT-8616, believed to be engaged in targeted exploitation of SD-WAN environments.
Unlike opportunistic attacks, this campaign demonstrates:
- Exploitation of authentication bypass vulnerabilities
- Use of public proof-of-concept (PoC) exploits
- Deployment of webshell-based persistence mechanisms
- Post-compromise actions including:
SSH key insertionConfiguration tamperingPrivilege escalation attempts.
Additionally, multiple unrelated threat clusters have leveraged the same vulnerabilities, indicating broad attacker interest and rapid weaponization.
Primary Targets
- Cisco Catalyst SD-WAN Controller (vSmart)
- Cisco Catalyst SD-WAN Manager (vManage)
- Enterprise environments using centralized SD-WAN orchestration
- Organizations with internet-exposed SD-WAN management interfaces
Vulnerability Details
CVE-2026-20182
- Type: Authentication Bypass (Unauthenticated Access)
- CVSS Score: 10.0 (Critical)
- EPSS Score: 31.70%
- Impact: Enables attackers to gain administrative access without credentials
- Affected Systems: Cisco SD-WAN Controller and Manager
Tactics and Techniques
- TA0001 – Initial Access: Authentication bypass using exposed SD-WAN interfaces
- TA0002 – Execution: Remote command execution via webshell deployment
- TA0003 – Persistence: Deployment of JSP-based webshells (e.g., XenShell, Godzilla, Behinder)
- TA0005 – Defense Evasion: Use of legitimate tools and minimal artifacts
- TA0007 – Discovery: System and network enumeration
- TA0008 – Lateral Movement: Access expansion via compromised credentials
Indicators of Compromise (IOCs)
Network Indicators
- 38.181.52[.]89
- 89.125.244[.]33
- 71.80.85[.]135
- 212.83.162[.]37
Malware / Tooling Observed
- XenShell (JSP webshell) – primary exploitation tool
- Godzilla Webshell
- Behinder Webshell
- NimPlant (modified)
- Sliver implant (red-team framework)
- AdaptixC2 agent
- XMRig cryptominer
Infection Method
Initial Access
Attackers exploited SD-WAN vulnerabilities to bypass authentication and access systems without credentials.
Exploitation
Successful exploitation allowed attackers to:
- Gain administrative access
- Inject and execute commands remotely
- Modify system configurations
Payload Delivery
Attackers deployed:
- JSP webshells (XenShell, Godzilla, Behinder)
- Lightweight post-exploitation tools
This enabled:
- Minimal disk footprint
- Rapid deployment
Execution & Persistence
Persistence mechanisms included:
- Webshell access
- SSH key insertion
- System configuration changes
Attackers avoided heavy malware and relied on:
- Native tools
- Memory-based execution
Command and Control (C2)
- Communication via compromised SD-WAN interfaces
- Use of external infrastructure and tunneling tools
- Overlap with known ORB (Operational Relay Box) networks
Attack Flow
Initial Access (Auth Bypass CVEs) -> Administrative Access -> Webshell Deployment (XenShell / variants) -> Execution & Persistence -> Post-Compromise Actions (SSH keys, config changes) -> Command and Control (external infrastructure)
Mitigation Steps
- Apply vendor patches immediately
- Restrict access to SD-WAN management interfaces
- Disable unnecessary external exposure
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.
