---
title: "CVE-2026-20182: Cisco SD-WAN Active Exploitation"
url: https://daily.dev/posts/cve-2026-20182-cisco-sd-wan-active-exploitation-catdnwdby
source_url: https://www.tenable.com/blog/faq-about-the-continued-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities-uat-8616
type: article
source: "Tenable Blog"
published: 2026-05-31T07:42:30.813Z
updated: 2026-05-31T08:21:23.163Z
tags: ["security", "vulnerability"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CVE-2026-20182: Cisco SD-WAN Active Exploitation

**[Tenable Blog](https://daily.dev/sources/tenable-blog)** · 6 min read · 0 upvotes · 0 comments

## Summary

Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation. CVE-2026-20182 (CVSSv3 10.0) was disclosed May 14, 2026, and is being exploited as a zero-day by a sophisticated threat actor designated UAT-8616, which has targeted Cisco SD-WAN infrastructure since at least 2023. Ten additional threat clusters began exploiting a related CVE chain (CVE-2026-20133, CVE-2026-20128, CVE-2026-20122) after public PoC code was released. Successful exploitation grants privileged access to SD-WAN Controllers, enabling NETCONF-based network configuration manipulation across the entire SD-WAN fabric. Post-compromise activities include SSH key injection, malicious account creation, and log clearing. CISA issued Emergency Directive 26-03 with a May 17 remediation deadline and added all five CVEs to its Known Exploited Vulnerabilities catalog. Patches are available for all supported releases. IoCs include suspicious auth.log entries, unauthorized SSH keys, and unexpected software downgrades.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.tenable.com/blog/faq-about-the-continued-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities-uat-8616>

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/cve-2026-20182-cisco-sd-wan-active-exploitation-catdnwdby)
