Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Affected vendor/product: Cisco Catalyst SD-WAN
Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CISA KEV date added: 2026-05-14
Due date: 2026-05-17
Known ransomware campaign use: Unknown