SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs

In-the-Wild Exploitation of Cisco SD-WAN Flaws Leading to Unauthorized Administrative Access

Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging

May 18, 20263 min read

Threat actors are actively targeting enterprise Cisco Catalyst SD-WAN infrastructure, exploiting authentication bypass and chained vulnerabilities to gain unauthorized administrative access. Recent threat intelligence from Cisco Talos highlights ongoing in-the-wild exploitation campaigns leveraging multiple vulnerabilities to compromise SD-WAN controllers an management platforms.

These attacks reflect a growing trend in cyber operations:
targeting network orchestration layers (SD-WAN controllers and managers) to achieve centralized control over distributed network environments, enabling privilege escalation, persistence, and lateral movement.

Background on Threat Activity

Cisco Talos attributes part of this activity to a sophisticated threat cluster tracked as UAT-8616, believed to be engaged in targeted exploitation of SD-WAN environments.

Unlike opportunistic attacks, this campaign demonstrates:

  • Exploitation of authentication bypass vulnerabilities
  • Use of public proof-of-concept (PoC) exploits
  • Deployment of webshell-based persistence mechanisms
  • Post-compromise actions including:
    SSH key insertionConfiguration tamperingPrivilege escalation attempts.

Additionally, multiple unrelated threat clusters have leveraged the same vulnerabilities, indicating broad attacker interest and rapid weaponization.

Primary Targets

  • Cisco Catalyst SD-WAN Controller (vSmart)
  • Cisco Catalyst SD-WAN Manager (vManage)
  • Enterprise environments using centralized SD-WAN orchestration
  • Organizations with internet-exposed SD-WAN management interfaces

Vulnerability Details

CVE-2026-20182

  • Type: Authentication Bypass (Unauthenticated Access)
  • CVSS Score: 10.0 (Critical)
  • EPSS Score: 31.70%
  • Impact: Enables attackers to gain administrative access without credentials
  • Affected Systems: Cisco SD-WAN Controller and Manager

Tactics and Techniques

  • TA0001 – Initial Access: Authentication bypass using exposed SD-WAN interfaces
  • TA0002 – Execution: Remote command execution via webshell deployment
  • TA0003 – Persistence: Deployment of JSP-based webshells (e.g., XenShell, Godzilla, Behinder)
  • TA0005 – Defense Evasion: Use of legitimate tools and minimal artifacts
  • TA0007 – Discovery: System and network enumeration
  • TA0008 – Lateral Movement: Access expansion via compromised credentials

Indicators of Compromise (IOCs)

Network Indicators

  • 38.181.52[.]89
  • 89.125.244[.]33
  • 71.80.85[.]135
  • 212.83.162[.]37

Malware / Tooling Observed

  • XenShell (JSP webshell) – primary exploitation tool
  • Godzilla Webshell
  • Behinder Webshell
  • NimPlant (modified)
  • Sliver implant (red-team framework)
  • AdaptixC2 agent
  • XMRig cryptominer

Infection Method

Initial Access

Attackers exploited SD-WAN vulnerabilities to bypass authentication and access systems without credentials.

Exploitation

Successful exploitation allowed attackers to:

  • Gain administrative access
  • Inject and execute commands remotely
  • Modify system configurations

Payload Delivery

Attackers deployed:

  • JSP webshells (XenShell, Godzilla, Behinder)
  • Lightweight post-exploitation tools

This enabled:

  • Minimal disk footprint
  • Rapid deployment

Execution & Persistence

Persistence mechanisms included:

  • Webshell access
  • SSH key insertion
  • System configuration changes

Attackers avoided heavy malware and relied on:

  • Native tools
  • Memory-based execution

Command and Control (C2)

  • Communication via compromised SD-WAN interfaces
  • Use of external infrastructure and tunneling tools
  • Overlap with known ORB (Operational Relay Box) networks

Attack Flow

Initial Access (Auth Bypass CVEs) -> Administrative Access -> Webshell Deployment (XenShell / variants) -> Execution & Persistence -> Post-Compromise Actions (SSH keys, config changes) -> Command and Control (external infrastructure)

Mitigation Steps

  • Apply vendor patches immediately
  • Restrict access to SD-WAN management interfaces
  • Disable unnecessary external exposure

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open What Is Patch Tuesday? A Complete Guide
What Is Patch Tuesday? A Complete Guide

Point of View

What Is Patch Tuesday? A Complete Guide

Patch Tuesday is Microsoft's monthly security release cycle. See how security and IT teams should review, prioritize, test, deploy, and verify updates while preparing for off-cycle fixes.

Oct 7, 2026

Open Zero-Day Patching: How to Respond Fast
Zero-Day Patching: How to Respond Fast

Point of View

Zero-Day Patching: How to Respond Fast

Zero-day response starts before a fix exists. See how teams can identify affected assets, reduce exposure, prepare emergency deployment, investigate compromise, and verify remediation.

Oct 5, 2026

Open Patch Management vs Vulnerability Management: What's the Difference?
Patch Management vs Vulnerability Management: What's the Difference?

Point of View

Patch Management vs Vulnerability Management: What's the Difference?

Patch management deploys software fixes, while vulnerability management covers the broader path from finding and prioritizing weaknesses to treatment and verification.

Oct 5, 2026

Open Cloud Patch Management: Challenges and Solutions
Cloud Patch Management: Challenges and Solutions

Point of View

Cloud Patch Management: Challenges and Solutions

Cloud patching requires teams to manage more than running virtual machines. See how shared responsibility, short-lived resources, base images, automation, maintenance planning, and verification affect patching in cloud environments.

Oct 5, 2026

In-the-Wild Exploitation of Cisco SD-WAN Flaws Leading to Unauthorized | SecPod