CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

Cybersecurity experts are sounding the alarm as a critical vulnerability has been added to the US government’s Known Exploited Vulnerabilities (KEV) catalog. The US Cybersecurity and Infrastructure Security Agency (CISA) has identified an authentication bypass flaw in Cisco’s Catalyst SD-WAN Manager, allowing attackers to exploit the vulnerability with relative ease.

This issue affects organizations that use Cisco’s SD-WAN technology for secure network management and monitoring. The vulnerability allows unauthenticated users to access sensitive features of the system, including configuration settings and user credentials. In other words, an attacker can potentially gain administrative access without being detected or needing to know any passwords.

The exploit works by leveraging a weakness in the SD-WAN Manager’s API, which is used for communication between the device and the management console. When a malicious actor sends a specifically crafted request to the API, it creates a backdoor that allows them to bypass authentication checks. This means they can access areas of the system that would normally be off-limits, such as configuration settings or user credentials.

The significance of this vulnerability lies in its potential for lateral movement within an organization’s network. If exploited successfully, attackers could use this weakness to gain a foothold and move undetected through the network, creating further vulnerabilities and increasing their chances of achieving their goals. This is particularly concerning given that many organizations rely on SD-WAN technology for secure remote access and management.

The addition of this vulnerability to the KEV catalog serves as a stark reminder of the importance of ongoing security monitoring and patching. Organizations that have not yet applied the necessary updates are at risk of being exploited by attackers who may be actively scanning for vulnerable systems. With the increasing sophistication of cyber threats, it is essential for organizations to prioritize their cybersecurity posture and take proactive steps to protect themselves against potential attacks.

To mitigate this vulnerability, we recommend that organizations update their SD-WAN Manager software to the latest version available from Cisco. Regularly monitoring system logs and network activity can also help identify potential security incidents early on. Furthermore, implementing robust access controls and ensuring that all users are using strong, unique passwords will further reduce the risk of an attacker successfully exploiting this vulnerability. By taking these precautions, organizations can significantly reduce their exposure to this critical weakness.


Source: The Hacker News — 2026-10-01