Critical Cisco SD-WAN Vulnerabilities Exposed: Bypass Access Controls and Manipulate File Paths
Cisco has released critical security hardening updates for its Catalyst SD-WAN Software to address multiple vulnerabilities that could allow authenticated attackers to bypass access controls and manipulate file paths. The company confirmed that no workarounds are available, making it essential for organizations operating vulnerable Catalyst SD-WAN releases to prioritize upgrading to a fixed release.
The critical vulnerabilities, rated CVSS 9.9, were discovered during internal testing using established security-testing processes and frontier AI models. The issues affect Catalyst SD-WAN installations regardless of device configuration and are tracked under Cisco advisory cisco-sa-hardening-sdwan-faLcR3K.
The impacted environments include on-premises deployments, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government (FedRAMP). Cisco published the advisory on August 5, 2026, following an internal security review by its Catalyst SD-WAN engineering team.