2026-06-16NOTABLEexploitedCisco Catalyst SD-WAN Manager CVE-2026-20262: authenticated arbitrary file write to root RCE
UAT-8616
actor · actor:uat-8616
UAT-8616, Sophisticated actor exploiting Cisco SD-WAN infrastructure since 2023
Coverage
4
first 2026-05-15 → last 2026-06-16
Latest activity
2026-09-05
CVE-2026-46300, Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public
Peak priority
notable
4 notable
Targets
telco
sectors: telco, public-sector, energy
Sources cited
31
19 hosts
2026-05-154 appearances2026-06-16
Action items (2)
Do-now tasks recorded on the entries about UAT-8616, newest first. Check the date before acting on an older one.
- Apply Linux kernel security updates to patch CVE-2026-46300 "Fragnesia", Linux kernel LPE via xfrm ESP-in-TCP with a working public PoC; the vulnerability enables any local user to escalate to root. Critical for shared compute environments (VPS, container hosts, HPC clusters, university Linux systems). Apply the kernel update from your distribution and reboot; where immediate patching is not feasible, disable the2026-05-15CVE-2026-46300
xfrm_espintcpmodule and restrictCAP_NET_ADMINcapability. - Emergency upgrade Cisco Catalyst SD-WAN Controller and Manager to a fixed release (20.9.9.1 / 20.12.7.1 / 20.15.5.2 / 20.18.2.2 / 26.1.1.1 per your release train), CVE-2026-20182 (CVSS 10.0) has no workaround and is actively exploited by UAT-8616; companion February 2026 CVEs are being exploited by 10+ additional clusters on the same infrastructure. If immediate upgrade is not possible, apply an ACL restricting access to UDP/12346 to known device IPs as a temporary partial control.2026-05-15UAT-8616 exploits Cisco Catalyst SD-WAN…
Defender insights
What each entry about UAT-8616 tells a defender to do, newest first.
Detection
Detection
Story timeline
- 2026-06-16Cisco Catalyst SD-WAN Manager CVE-2026-20262: authenticated arbitrary file write to root RCE
- 2026-05-15UAT-8616 exploits Cisco Catalyst SD-WAN CVE-2026-20182; 10+ clusters exploit companion February 2026 CVEs; CISA Emergency Directive ED-26-03 issued
- 2026-05-15CVE-2026-46300, Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public
- 2026-05-15Cisco Catalyst SD-WAN: CVE-2026-20182 Authentication Bypass and UAT-8616 Kill Chain
Hunting pivots
CVEs (exploited first)
ATT&CK techniques (17 across 9 tactics)
17 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Valid Accounts: Cloud Accounts · Exploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter
- PersistenceValid Accounts · Valid Accounts: Cloud Accounts · Account Manipulation · Account Manipulation: SSH Authorized Keys · Server Software Component · Server Software Component: Web Shell
- Privilege EscalationExploitation for Privilege Escalation · Valid Accounts · Valid Accounts: Cloud Accounts · Account Manipulation · Account Manipulation: SSH Authorized Keys · Escape to Host
- StealthIndicator Removal · Valid Accounts · Valid Accounts: Cloud Accounts
- Defense ImpairmentDisable or Modify Tools · Disable or Modify Tools: Clear Linux or Mac System Logs
- Lateral MovementRemote Services · Remote Services: SSH
- Command and ControlApplication Layer Protocol
- ImpactResource Hijacking
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1190Exploit Public-Facing Application×2
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1098.004Account Manipulation: SSH Authorized Keys×1
Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</code> file in SSH specifies the SSH keys that can be used for logging into the user account for which the file is configured. This file is usually found in the user's home directory under <code><user-home>/.ssh/authorized_keys</code> (or, on ESXi, `/etc/ssh/keys-<username>/authorized_keys`). Users may edit the system’s SSH config file to modify the directives `PubkeyAuthentication` and `RSAAuthentication` to the value `yes` to ensure public key and RSA authentication are enabled, as well as modify the directive `PermitRootLogin` to the value `yes` to enable root authentication via SSH. The SSH config file is usually located under <code>/etc/ssh/sshd_config</code>.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1505Server Software Component×2
Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×2
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×2
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-05-15/cve-2026-46300-linux-kernel-local-privilege-escalation-via-x · 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1098.004Account Manipulation: SSH Authorized Keys×1
Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</code> file in SSH specifies the SSH keys that can be used for logging into the user account for which the file is configured. This file is usually found in the user's home directory under <code><user-home>/.ssh/authorized_keys</code> (or, on ESXi, `/etc/ssh/keys-<username>/authorized_keys`). Users may edit the system’s SSH config file to modify the directives `PubkeyAuthentication` and `RSAAuthentication` to the value `yes` to ensure public key and RSA authentication are enabled, as well as modify the directive `PermitRootLogin` to the value `yes` to enable root authentication via SSH. The SSH config file is usually located under <code>/etc/ssh/sshd_config</code>.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1611Escape to Host×1
Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.
Evidence: 2026-05-15/cve-2026-46300-linux-kernel-local-privilege-escalation-via-x · ATT&CK page ↗
Stealth TA0005
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-06-16/cisco-catalyst-sd-wan-manager-cve-2026-20262-authenticated-a · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1685.006Disable or Modify Tools: Clear Linux or Mac System Logs×1
Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the `/var/log/` directory. Subfolders in this directory categorize logs by their related functions, such as:
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
Lateral Movement TA0008
T1021Remote Services×1
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
T1021.004Remote Services: SSH×1
Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
Impact TA0040
T1496Resource Hijacking×1
Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
Evidence: 2026-05-15/cisco-catalyst-sd-wan-cve-2026-20182-authentication-bypass-a · ATT&CK page ↗
Entries about UAT-8616 (4)
Earlier coverage (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616)×1
- Cisco Catalyst SD-WAN Manager web UI authenticated path traversal, arbitrary file write to root RCE; CISA KEV 2026-06-15×1
- Dirty Frag / Fragnesia×1
- Fragnesia, Linux kernel xfrm ESP-in-TCP LPE (PoC public)×1
Where this entity is cited
Source distribution
- attack.mitre.org11 (35%)
- blog.talosintelligence.com2 (6%)
- sec.cloudapps.cisco.com2 (6%)
- access.redhat.com1 (3%)
- aikido.dev1 (3%)
- api.first.org1 (3%)
- bleepingcomputer.com1 (3%)
- blog.packagist.com1 (3%)
- other11 (35%)
All cited sources (31)
- access.redhat.comRed Hat (RHSB-2026-003)https://access.redhat.com/security/vulnerabilities/RHSB-2026-003
- aikido.devAikido Securityhttps://www.aikido.dev/blog/dirty-frag
- api.first.orgFIRST.org EPSS APIhttps://api.first.org/data/v1/epss?cve=CVE-2026-46300
- attack.mitre.orgT1021.004 Remote Services: SSHhttps://attack.mitre.org/techniques/T1021/004/
- attack.mitre.orgT1059 Command and Scripting Interpreterhttps://attack.mitre.org/techniques/T1059/
- attack.mitre.orgT1068 Exploitation for Privilege Escalationhttps://attack.mitre.org/techniques/T1068/
- attack.mitre.orgT1070.002 Indicator Removal: Clear Linux or Mac System Logshttps://attack.mitre.org/techniques/T1070/002/
- attack.mitre.orgT1071 Application Layer Protocolhttps://attack.mitre.org/techniques/T1071/
- attack.mitre.orgT1078.004 Valid Accounts: Cloud Accountshttps://attack.mitre.org/techniques/T1078/004/
- attack.mitre.orgT1098.004 Account Manipulation: SSH Authorized Keyshttps://attack.mitre.org/techniques/T1098/004/
- attack.mitre.orgT1190 Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- attack.mitre.orgT1496 Resource Hijackinghttps://attack.mitre.org/techniques/T1496/
- attack.mitre.orgT1505.003 Server Software Component: Web Shellhttps://attack.mitre.org/techniques/T1505/003/
- attack.mitre.orgT1562.001 Impair Defenses: Disable or Modify Toolshttps://attack.mitre.org/techniques/T1562/001/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/
- blog.packagist.comPackagist bloghttps://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/
- blog.talosintelligence.comCisco Talos, 2026-05-14https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
- blog.talosintelligence.comTalos UAT-8616 deep dive, 2026-02-25https://blog.talosintelligence.com/uat-8616-sd-wan/
- cisa.govCISA ED-26-03https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems
- cveawg.mitre.orgMITRE CVE Program (Linux kernel CNA)https://cveawg.mitre.org/api/cve/CVE-2026-46300
- cyber.gov.auACSC hunt guide, 2026-02-25https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf
- depthfirst.comdepthfirst / NCSC-CHhttps://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability
- helpnetsecurity.comHelp Net Security, 2026-05-14https://www.helpnetsecurity.com/2026/05/14/fragnesia-cve-2026-46300-linux-lpe-vulnerability/
- microsoft.comMicrosoft Security Bloghttps://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/
- nvd.nist.govNVD, CVSS 6.5https://nvd.nist.gov/vuln/detail/CVE-2026-20262
- rapid7.comRapid7, 2026-05-14https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/
- sec.cloudapps.cisco.comCisco PSIRT advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
- sec.cloudapps.cisco.comCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- securityweek.comSecurityWeek, 2026-05-15https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-the-sixth-exploited-in-2026/
- theregister.comThe Registerhttps://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916
- wiz.ioWiz Research, 2026-05-13https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp