Hackers Break Into Unpatched Cisco SD-WAN Devices to Plant Webshells

Cisco's networking gear is under attack again. Cisco Talos, the security research arm of Cisco, says attackers are actively exploiting a serious flaw in Cisco Catalyst SD-WAN, the software many large organizations use to connect and manage their office networks over the internet. The bug, tracked as CVE-2026-20182, is an authentication bypass, meaning a remote attacker can skip the login process entirely. According to the Talos advisory, a successful break-in hands the attacker full administrative control over the affected system.

What's affected

The vulnerable products are Cisco Catalyst SD-WAN Controller (previously called vSmart) and Cisco Catalyst SD-WAN Manager (previously called vManage). These are the central management systems that direct traffic across an organization's network, so taking one over is a serious foothold. Talos is also tracking a second, much louder wave of attacks against three earlier Catalyst SD-WAN Manager flaws, CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122, that can be combined to gain remote access without logging in.

How the attack works

Talos attributes the CVE-2026-20182 activity, with high confidence, to a skilled group it calls UAT-8616, the same actor it previously tied to exploitation of a related SD-WAN flaw, CVE-2026-20127, which IntelFusions has covered separately. Once inside, UAT-8616 tried to add SSH keys (which would give it a permanent way back in), alter NETCONF configurations and escalate to root, the highest level of access. Talos says the group's infrastructure overlaps with Operational Relay Box (ORB) networks, a kind of disguised proxy used to hide an attacker's origin, and that this particular exploitation has been limited so far.

The second wave is the noisier one. Cisco shipped fixes and an advisory for the three February flaws back in February 2026, but many systems were never updated. After a group called ZeroZenX Labs published proof-of-concept attack code in March 2026, multiple sets of attackers grabbed it and used it to drop webshells, small hidden programs that let an intruder run commands on a server. The most common one, bundled with that code, is tracked by Talos as XenShell, and researchers also spotted variants of the Godzilla and Behinder webshells across at least ten separate activity clusters. Talos notes the ZeroZenX code wrongly labels its target as CVE-2026-20127, when the real flaws are the three February CVEs.

What you should do

Talos assesses with high confidence that unpatched Catalyst SD-WAN Manager and Controller systems will keep facing opportunistic attacks for as long as public proof-of-concept code is available. Organizations should apply Cisco's February and later advisories immediately, then hunt their systems for trouble: look for unexpected JSP (JavaServer Pages) files, unexplained SSH key additions and unfamiliar NETCONF changes, and treat any management system exposed to the internet as high risk. Defenders can also watch for the indicators Talos shared (defanged here): attack source addresses 38[.]181[.]52[.]89, 89[.]125[.]244[.]33 and 212[.]83[.]162[.]37, plus a cryptominer staging server at hxxp://83[.]229[.]126[.]195:8081/xmrig.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions