cbcvebase.
CVE-2026-20182
published 2026-05-14

CVE-2026-20182: May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-05-17
Exploited in the wild
EPSS
88.50%
99.8th percentile
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Affected

179 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan_manager< 20.9.9.120.9.9.1
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.10 < 20.12.5.420.12.5.4
ciscocatalyst_sd-wan_manager>= 20.12.6 < 20.12.6.220.12.6.2
ciscocatalyst_sd-wan_manager>= 20.13 < 20.15.4.420.15.4.4
ciscocatalyst_sd-wan_manager>= 20.15.5 < 20.15.5.220.15.5.2
ciscocatalyst_sd-wan_manager>= 20.16 < 20.18.2.220.18.2.2
ciscocatalyst_sd-wan_manager>= 26.1 < 26.1.1.126.1.1.1
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller
ciscocisco_catalyst_sd-wan_controller

Detection & IOCsextracted from sources · hover to see the quote

portUDP/12346
processvdaemon
path/var/log/auth.log
path/etc/passwd
path/etc/shadow
othertroot (rogue user account)
otherXenShell (JSP-based web shell)
otherGodzilla web shell
otherBehinder web shell
otherAdaptixC2 (malware agent compiled off the AdaptixC2 red teaming framework)
otherSliver C2 framework
otherXMRig miner
otherKScan asset mapping tool
otherNimPlant-based Nim backdoor
othergsocket (peer-based proxying and tunneling tool)
otherCredential stealer targeting admin hashdump, JWT key chunks, and AWS credentials for vManage
  • Audit /var/log/auth.log for 'Accepted publickey for vmanage-admin' entries from unknown or unauthorized IP addresses as an indicator of exploitation.
  • Hunt for suspicious peering events in logs: unauthorized peer connections at unexpected times, from unrecognized IPs, or involving device types inconsistent with the environment's architecture.
  • The exploit targets the 'vdaemon' service over DTLS on UDP port 12346; monitor for unexpected or anomalous DTLS traffic to this port on SD-WAN controllers.
  • Post-compromise, UAT-8616 attempted to add SSH keys, modify NETCONF configurations, and escalate to root privileges — monitor for unauthorized SSH key additions and NETCONF config changes.
  • Detect creation of hidden local accounts (e.g., 'troot') in /etc/passwd and /etc/shadow on SD-WAN controller systems as a post-exploitation indicator.
  • Monitor for malicious CSV file uploads to the SD-WAN Manager interface (e.g., filenames like evil_tenant.csv) as a vector for privilege escalation via CVE-2026-20245.
  • Threat actor infrastructure overlaps with Operational Relay Box (ORB) networks; correlate inbound connections to SD-WAN controllers against known ORB network indicators.
  • Detect web shell deployment (Godzilla, Behinder, XenShell variants) on SD-WAN systems; these allow operators to run arbitrary bash commands post-exploitation.
  • Use the SD-WAN advisory's 'Show Control Connections' guidance to audit active peering connections for unauthorized peers.
  • ·CVE-2026-20182 is a distinct vulnerability from CVE-2026-20127 — it is not a patch bypass. Both affect the same 'vdaemon' service/DTLS stack but are different issues.
  • ·Systems accessible over the internet with exposed ports are at increased risk; internet-facing SD-WAN controllers should be treated as highest priority for patching.
  • ·In the March 2026 second wave, Cisco confirmed the rogue peering connections did NOT leverage CVE-2026-20182; stolen certificates from a prior breach may have been used instead.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.