Cisco Releases Critical SD-WAN Security Updates Amid Multi-Vulnerability Alert
Cisco has released critical security hardening updates for its Catalyst SD-WAN Software to address multiple vulnerabilities that could allow authenticated attackers to bypass access controls and manipulate file paths.
The flaws, rated with maximum CVSS scores of 9.9, affect Catalyst SD-WAN installations regardless of device configuration and impact on-premises deployments, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government (FedRAMP).
Cisco confirmed that no workarounds are available, and organizations operating vulnerable Catalyst SD-WAN releases should prioritize upgrading to a fixed release. The company has released several versions with patches, including Cisco Catalyst SD-WAN 20.9.10 for the 20.9 release train and Cisco Catalyst SD-WAN 26.1.2 for the 26.1 release train.
The issues were discovered during internal testing using established security-testing processes and frontier AI models. Cisco PSIRT stated that it was not aware of any public exploitation or malicious use at the time of disclosure.