vulnerability
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
High
Summary
Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122). The activity, tracked under the UAT-8616 threat actor, involves unauthorized access and post-compromise actions, including the deployment of webshells like ‘XenShell’. This exploitation is occurring in the wild, highlighting the urgency for affected customers to apply available security updates.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
