Skip to content

CISA adds Cisco Catalyst SD-WAN Manager auth bypass to KEV: What small businesses should do now

If you manage Cisco SD-WAN gear, a new high-priority item landed in your security inbox today. A Cisco Catalyst SD-WAN Manager authentication bypass has been moved into CISA’s Known Exploited Vulnerabilities catalog, which means it’s considered actively exploited and urgent to address.

What happened

On a recent update, the Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager authentication bypass to its Known Exploited Vulnerabilities (KEV) catalog. Being listed in KEV signals that the vulnerability has seen exploitation in the wild and should be patched as a matter of priority. Cisco has published advisories and patches for affected versions, so organizations should review their SD-WAN Manager deployments to determine exposure and options for remediation.

KEV is used by organizations to prioritize patching, because it highlights vulnerabilities that threat actors are actively leveraging. Details can evolve as vendors release additional guidance, so it’s worth staying tuned to official advisories from Cisco and CISA.

Why it matters

For small businesses and IT teams, SD-WAN devices are critical because they control how your branch offices connect to the internet and to each other. An authenticated bypass in the management interface could let an attacker login without valid credentials, potentially gain control over the device, and pivot to other systems. That can lead to data exposure, service disruption, or network-wide compromises if left unpatched.

Even if you’re not a large enterprise, you likely have at least one SD-WAN device or virtual appliance in use. A known exploited vulnerability targeting such devices is a reminder to keep firmware, software, and access controls up to date.

Practical steps readers can take

  • Inventory – Identify all Cisco Catalyst SD-WAN Manager instances in your environment. Note versions and patch status.
  • Patch promptly – Apply the latest Cisco patches or maintenance releases that address the KEV-listed authentication bypass. If you cannot patch immediately, prioritize workarounds from Cisco advisories.
  • Limit exposure – Restrict management interfaces to trusted networks, VPNs, or jump hosts. Disable or restrict remote management where not needed.
  • Strengthen access – Enforce MFA for management interfaces and rotate credentials for SD-WAN managers and admin accounts.
  • Monitor and alert – Enable logging for management login attempts, failed authentications, and unexpected configuration changes. Set up alerts for anomalous access patterns.
  • Backups and recovery – Verify that device configurations are backed up, and test restoration procedures in case of a compromise.
  • Documentation – Capture a quick action plan for incident response specific to SD-WAN devices so your team can respond quickly if needed.

If you’re unsure whether your environment is affected, review the official Cisco advisory and CISA KEV entry. Details may change as advisories are updated, so keep an eye on vendor and government notices.

Final thought

This KEV listing is a practical reminder: even core network gear needs regular patching and sensible access controls. Start with a quick asset check, apply the latest fixes, and tighten access right away. Small steps now can prevent bigger headaches later.

Leave a Reply

Your email address will not be published. Required fields are marked *