UAT-8616 Cisco SD-WAN Rogue Peering and Auth Bypass (CVE-2026-20127/20182)

Detects malicious activities targeting Cisco Catalyst SD-WAN infrastructure, including connections from known malicious IP addresses (UAT-8616), unauthenticated vManage API access attempts indicative of exploitation (CVE-2026-20182), and anomalous control-plane signaling (OMP/DTLS/NETCONF) from unauthorized external sources.