Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
Plan PatchCVSS 9.9cisco-sa-hardening-sdwan-faLcR3KAug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Cisco Catalyst SD-WAN Controller and Manager contain multiple internally discovered vulnerabilities grouped by Common Weakness Enumeration (CWE) classes. These vulnerabilities were identified during Cisco's comprehensive security review and are not currently known to be actively exploited. Cisco has released software hardening updates that address these issues. No workarounds are available.
What this means
What could happen
An authenticated attacker with access to SD-WAN management interfaces could execute remote commands or manipulate SD-WAN network configuration and traffic routing, potentially causing denial of service or unauthorized changes to network operations.
Who's at risk
This affects organizations running Cisco Catalyst SD-WAN solutions for wide-area network connectivity, including service providers and enterprises using SD-WAN Controllers and Managers for centralized network management and policy deployment.
How it could be exploited
An attacker with valid credentials for the SD-WAN Controller or Manager can authenticate to the management interface and exploit the underlying vulnerabilities to gain command execution or modify network policies, affecting all connected SD-WAN sites.
Prerequisites
- Valid credentials for Cisco Catalyst SD-WAN Controller or Manager interface
- Network access to the SD-WAN management interface (port 443 or similar)
- Authentication to the management system (requires valid user account)
requires authenticationhigh CVSS score (9.9)remotely exploitableaffects network management and control
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Catalyst SD-WAN ControllerAll versionsFix available
Catalyst SD-WAN ManagerAll versionsFix available
Remediation & Mitigation
0/4
Do now
0/2HARDENINGRestrict management interface access to authorized administrators only using firewall rules or access control lists
HARDENINGReview and enforce strong authentication policies (complex passwords, multi-factor authentication) for SD-WAN management accounts
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Catalyst SD-WAN Controller
HOTFIXUpdate Cisco Catalyst SD-WAN Controller to the patched version released by Cisco
Catalyst SD-WAN Manager
HOTFIXUpdate Cisco Catalyst SD-WAN Manager to the patched version released by Cisco
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/7325513d-794a-4af1-be12-3052b99d5a9cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.