Cisco SD-WAN admin takeover path is under active attack
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, October 1st, 2026.
Cisco Catalyst SD-WAN Manager is facing an actively exploited route to administrative control. An attacker who has no credentials can send a crafted A P I request, bypass authentication, and reach the system with the privileges of the admin user. The issue affects deployments regardless of configuration. Fixed releases are available, but Cisco has provided no workaround. CISA has also added the issue to its Known Exploited Vulnerabilities catalog and set an October 3rd deadline for federal agencies.
This matters because a centralized network-management platform can give an intruder significant visibility and control. Internet-facing systems have the greatest immediate exposure. Restricting access can reduce risk while teams prepare an update, but it’s only a temporary measure. Leaders should treat this as emergency maintenance rather than wait for the next routine patch window. Defenders should review the identified service logs for suspicious encoded requests and unauthorized activity, while allowing for possible false positives during normal operations. The broader lesson is that authentication failures in centralized control systems require both rapid remediation and a compromise assessment. Upgrade to a fixed release now, restrict management access, and investigate exposed systems for prior compromise.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.