Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1154+ Articles
126+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026
Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026
NEWS

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

Cisco has patched CVE-2026-20182, a zero-day in Catalyst SD-WAN Manager that has been actively exploited in targeted attacks by sophisticated threat actor...

Dylan H.

News Desk

May 16, 2026
3 min read

Cisco has disclosed and patched CVE-2026-20182, a zero-day vulnerability in the Catalyst SD-WAN Manager platform that was already under active exploitation in targeted attacks before the fix was available. The disclosure marks the sixth Cisco SD-WAN zero-day to be exploited in the wild so far in 2026 — a troubling pattern that underscores how aggressively sophisticated threat actors are targeting enterprise WAN infrastructure.

What Is CVE-2026-20182?

CVE-2026-20182 is an authentication bypass vulnerability affecting the Cisco Catalyst SD-WAN Controller. The flaw allows a remote, unauthenticated attacker to bypass normal authentication controls and gain unauthorized access to the management plane. From there, attackers can manipulate routing policies, intercept traffic, or use the foothold to move laterally across connected enterprise networks.

Cisco's advisory rated the vulnerability as high severity and confirmed it had been exploited in targeted attacks prior to patch availability.

UAT-8616: The Persistent Threat Behind the Attacks

Cisco's Talos intelligence team attributed the exploitation campaign to UAT-8616, a sophisticated threat group that has been systematically targeting Cisco network infrastructure throughout 2026. UAT-8616 is not a newcomer — the group has been observed across all six Cisco SD-WAN zero-day exploitation campaigns this year, demonstrating:

  • Pre-patch intelligence — the group exploits flaws before vendors complete the patch cycle.
  • Targeted operations — attacks focus on specific high-value enterprise and government networks rather than opportunistic mass scanning.
  • Cross-platform persistence — the group has also been linked to exploitation of Cisco firewall vulnerabilities, suggesting deep knowledge of Cisco's product portfolio.

Researchers note that UAT-8616's operational tempo is consistent with a well-resourced nation-state or state-sponsored actor.

A Year of Cisco SD-WAN Zero-Days

CVE-2026-20182 is the latest in a series that has kept Cisco administrators scrambling in 2026:

#CVEComponentActor
1CVE-2026-20127SD-WAN ManagerUAT-8616
2CVE-2026-20122Catalyst SD-WAN ManagerUAT-8616
3Prior flawCisco FirewallsLinked campaign
4Prior flawSD-WAN vManageUnknown
5Prior flawSD-WAN ControllerUAT-8616
6CVE-2026-20182SD-WAN ControllerUAT-8616

The pattern suggests UAT-8616 has developed or acquired a substantial vulnerability research capability specifically targeting Cisco's SD-WAN stack.

Recommendations

Patch immediately. Cisco has released fixes — administrators running Catalyst SD-WAN Manager should apply the update on an emergency basis.

Additional hardening steps:

  • Restrict management plane access — SD-WAN management interfaces should never be exposed to the internet. Enforce access from trusted IP ranges only.
  • Enable SD-WAN audit logging — ensure all management-plane actions are logged and forwarded to a SIEM for anomaly detection.
  • Monitor for lateral movement — following any SD-WAN compromise, assume the attacker has visibility into routing configuration; audit connected segments for signs of pivoting.
  • Review PSIRT advisories regularly — Cisco's Product Security Incident Response Team has issued multiple advisories this year; set up automated alerts.
  • Consider network segmentation — isolate SD-WAN management traffic on a dedicated out-of-band network.

Broader Context

The six-zero-day pattern in a single product line over one year is exceptional. Enterprise networking equipment is an increasingly high-priority target for sophisticated threat actors because control of the WAN fabric provides passive visibility across all connected traffic without deploying endpoint malware. Organizations relying on Cisco SD-WAN for hybrid or multi-cloud connectivity should treat this threat with board-level urgency.

References

  • SecurityWeek — Cisco Patches Another SD-WAN Zero-Day
  • Cisco Security Advisories (PSIRT)
#Zero-Day#CVE#Cisco#SD-WAN#Network-Security

Related Articles

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

Cisco has patched a maximum-severity authentication bypass flaw in its Catalyst SD-WAN Controller that has already been exploited in limited attacks....

5 min read

Cisco Zero-Day Under Ongoing Attack by Persistent Threat Group

The threat group UAT-8616 is actively exploiting a new Cisco SD-WAN zero-day and has been linked to multiple prior Cisco firewall and SD-WAN vulnerability...

4 min read

Interlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure

CVE-2026-20131, a maximum-severity CVSS 10.0 insecure deserialization flaw in Cisco Firepower Management Center, was exploited by Interlock ransomware as...

4 min read
Back to all News