Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager. This vulnerability allows an unauthenticated, remote attacker to bypass authentication and gain administrative privileges on the affected system. The issue arises because the peering authentication mechanism is not functioning correctly. Exploitation involves sending crafted requests to the system, which could enable the attacker to log in as a high-privileged, non-root user. With this access, the attacker could utilize NETCONF to manipulate network configurations within the SD-WAN fabric.

Impact

Exploitation of this vulnerability could lead to unauthorized administrative access on the affected system, allowing an attacker to manipulate network configurations via NETCONF.

Remediation

Cisco has released software updates to address this vulnerability. Affected users should upgrade to the latest version of Cisco Catalyst SD-WAN Software. For specific upgrade instructions, consult the Cisco Catalyst SD-WAN Upgrade Matrix or the Cisco Product Security Incident Response Team (PSIRT) guidance.

Added: Mar 13, 2026, 1:47 PM
Updated: Mar 13, 2026, 1:47 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
9.8
remediation
8.3
relevance
3.2
threat
9.1
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.