INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco Catalyst SD-WAN Manager Exploit Code Found

| 2026-06-06 04:19 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The situation with Cisco's SD-WAN software has become increasingly critical, with multiple vulnerabilities being exploited in the wild. The most recent and severe of these is CVE-2026-20245, which affects On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). This vulnerability has been linked to authentication bypasses that could enable unauthorized access to administrative privileges on susceptible systems. The threat activity cluster dubbed UAT-8616 is also associated with the abuse of CVE-2026-20127, another case of authentication bypass impacting the same component. As a result, customers are advised to upgrade their SD-WAN software and apply fixes for CVE-2026-20182 by May 14, 2026.
Technical Mitigations AI-generated
* Implement secure file uploads: Ensure that all file uploads to the SD-WAN system, including those from users and administrators, follow a secure protocol such as HTTPS or SFTP. This can be achieved by validating user-supplied input before storing it on the server. * Use Content Security Policy (CSP): Implement CSP to restrict which sources of content are allowed in web pages that your SD-WAN system will serve. This can help prevent attackers from injecting malicious scripts into the system. * Regularly update and patch software: Ensure that all SD-WAN components, including Catalyst SD-WAN Manager, Unified Communications Manager, and other affected systems, receive regular security patches to fix known vulnerabilities like CVE-2026-20245. * Implement network segmentation: Segment your network to isolate sensitive data and systems from the rest of the network. This can help prevent attackers from exploiting a vulnerability in one system by compromising another. * Monitor for suspicious activity: Continuously monitor logs and other indicators of compromise (IoCs) for signs of exploitation or unauthorized access to SD-WAN systems.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sc•••••.log
vc•••••.sh
ch•••••.csv
vc•••••.sh
vs•••••.csv
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20230CVE-2026-20230 CVE-2026-20133CVE-2026-20133 CVE-2026-20127CVE-2026-20127 CVE-2026-20128CVE-2026-20128 CVE-2026-20045CVE-2026-20045 CVE-2025-20309CVE-2025-20309 CVE-2026-20182CVE-2026-20182 CVE-2022-20775CVE-2022-20775 CVE-2026-20245CVE-2026-20245 CVE-2024-20253CVE-2024-20253 CVE-2026-20122CVE-2026-20122
Target & Sectors
Global Scope
Incident Timeline
‎2026/05/07
Threat actors used a previously unknown vulnerability (CVE-2026-20182) in Cisco Catalyst SD-WAN Manager to target systems.
vulnerability CVE-2026-20182
‎May 14, 2026
Threat actors used a vulnerability in Cisco Catalyst SD-WAN Manager to exploit CVE-2026-20182, actively exploiting it.
vulnerability CVE-2026-20182
organisation SD-WAN
organisation Cisco SD-WAN
organisation CVE-2022
data_breach 5 vsmart_serial_numbers_safe.csv Jun
organisation Unified Communications
‎Jun 04, 2026
Threat actors exploited CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain unauthorized access.
‎Jun 06, 2026
Threat actors exploited CVE-2026-20245 in the Cisco Catalyst SD-WAN Manager, using it to target On-Prem Deployment and Cisco SD-WAN Cloud-Pro.
organisation CVSS
organisation CLI
organisation SD-WAN vManage
organisation Google Mandiant
‎2026/06/06
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available.
organisation Cisco Catalyst SD-WAN
organisation Flaw Actively Exploited
organisation CVSS
organisation Cisco Patches CVE-2026-20230
organisation Unified CM
organisation Exploit Code Goes Public
organisation Product Security Incident Response Team
organisation COP
organisation CVE-2026
organisation Unified Communications
organisation Vulnerability / Network Security
organisation Catalyst SD-WAN
organisation SSH
organisation PoC
organisation Session Management Edition
organisation Cisco
organisation Critical
organisation WebDialer
organisation Cisco Unified CM Administration
organisation Cisco Unified Serviceability
organisation Tools > Control Center - Feature Services
organisation the Cisco WebDialer
organisation CTI
organisation the Unified CM Administration
organisation Cisco Unified CM
victims 1 company
organisation SSD Secure Disclosure
organisation Critical Cisco Unified
organisation Cisco CallManager
organisation PSIRT
organisation SecurityAffairs
organisation SIR
organisation the Cisco Unified CM Administration
organisation EDR
‎September 2026
Threat actors exploited the Cisco Catalyst SD-WAN Manager CVE-2026-20245 flaw in a 15SU5 Service Update.
organisation COP
organisation Tools > Service Activation
Tactical Metrics
Metrics
data_breach
5
Vsmart_Serial_Numbers_Safe.Csv Jun
Metrics
victims
1
Company