Cisco warned of an active exploitation targeting Cisco Catalyst SD-WAN appliances.
The peering authentication vulnerability (CVE-2026-20182) allows for remote unauthenticated attacker to bypass login controls and gain administrative privileges. Cisco Talos research notes exploitation of the flaw appears limited thus far.
A Cisco advisory said users should first collect admin-tech files from all control components, then upgrade every SD-WAN control component in the environment to a fixed release. Patched versions of the Cisco Catalyst software range from 20.9.9.1 through 20.18.2.2 depending on the deployment.
Customers were also advised to start a Cisco support case and upload the admin-tech bundles for scanning. The firm warned users not to wait for scan results before upgrading.
Talos attributed the campaign to hacking group UAT-8616, who were previously linked with a separate campaign targeting Catalyst devices. That exploit drew the attention of countries across the Five Eyes alliance.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) would go on to warn that three more Cisco Catalyst SD-WAN Manager bugs were under exploit. The agency explained that those vulnerabilities were "frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise."
Comments