UAT-8616 CVE-2026-20127/20182 vManage SSH Auth from Known Threat Actor IPs

Detects successful SSH authentication to administrative accounts ('vmanage-admin' or 'admin') on Cisco Catalyst SD-WAN Manager (vManage) devices originating from IP addresses associated with the threat actor UAT-8616. This activity relates to exploits targeting CVE-2026-20127 and CVE-2026-20182 for unauthorized access via authentication bypass or certificate abuse.