Cisco Catalyst SD-WAN Controller Authentication Bypass | MSSP Advisory

Critical
DateMay 15, 2026
📋Executive Summary
CISA added a maximum-severity authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller to their Known Exploited Vulnerabilities list. The flaw allows attackers to completely bypass authentication controls and gain unauthorized access to the management interface. Active exploitation is confirmed in the wild.
⚠️Why It Matters for MSSPs
SD-WAN controllers manage network routing and security policies across your entire client base, making them crown jewel targets for lateral movement. Your clients trust you to monitor their network infrastructure, and an authentication bypass on their primary WAN controller means total network compromise before you even see the first alert.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.