CVE-2026-20127/20182 Cisco SD-WAN vManage Auth Bypass – Unauthenticated API & Rogue Peering

Detects anomalous access to Cisco SD-WAN Manager (vManage) infrastructure. This includes unauthenticated REST API access, unauthorized NETCONF sessions, and suspicious OMP/DTLS peering connections, which may indicate exploitation of vulnerabilities (such as CVE-2026-20127 or CVE-2026-20182) or unauthorized management access.