CISA Flags Cisco SD‑WAN Manager Auth Bypass as Actively Exploited Threat
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Wednesday that a critical authentication‑bypass flaw in Cisco's Catalyst SD‑WAN Manager has been added to its Known Exploited Vulnerabilities (KEV) list after evidence of active exploitation surfaced.
The vulnerability allows an attacker to circumvent the manager's login controls and gain unauthenticated access to the SD‑WAN orchestration console. Once inside, threat actors could modify routing policies, intercept traffic, or deploy additional malicious code across the connected network, posing a severe risk to enterprises that rely on the platform for branch connectivity.
Cisco Catalyst SD‑WAN Manager is a core component in many corporate and service‑provider networks, enabling centralized configuration and monitoring of distributed sites. As organizations increasingly adopt software‑defined networking to simplify operations and reduce costs, the exposure of a remote‑access weakness in such a widely deployed system raises the stakes for both private and public sector entities.
The KEV program is designed to highlight vulnerabilities that have been observed in the wild and are actively weaponized. By elevating this Cisco flaw to the KEV roster, CISA signals to federal agencies and other critical‑infrastructure operators that the issue warrants immediate remediation, rather than being treated as a routine patch cycle item.
Cisco responded to the disclosure by issuing an emergency security advisory and publishing patches that address the authentication bypass. The company advises customers to apply the updates without delay, enable multi‑factor authentication where possible, and review logs for any signs of unauthorized access attempts.
While specific threat actors have not been publicly identified, the nature of the flaw—granting full control over a network management interface—makes it attractive to both nation‑state groups seeking espionage footholds and cybercriminals looking to extort victims through ransomware or data theft.
Security teams are urged to prioritize the Cisco update, verify that all SD‑WAN devices are running the patched firmware, and monitor for indicators of compromise associated with the exploit. CISA indicated that it will continue to track activity related to the vulnerability and provide further guidance as new information emerges.
Comments (0)
Be the first to comment.
Join the discussion