Cisco Catalyst SD-WAN Controller Authentication Bypass RCE | MSSP Advisory
CriticalCredible Report
DateMay 15, 2026
📋Executive Summary
Cisco disclosed a maximum severity authentication bypass vulnerability in Catalyst SD-WAN Controller and Manager platforms that allows unauthenticated remote attackers to gain administrative privileges. The flaw is actively exploited in the wild and has no workarounds available. Cisco confirmed limited exploitation starting in May 2024 and released software updates to address the vulnerability.
⚠️Why It Matters for MSSPs
SD-WAN controllers are critical network infrastructure that many MSSP clients rely on for site connectivity and traffic management. If your own stack includes Cisco SD-WAN management or if clients run these platforms, attackers can gain full administrative control over network routing and potentially pivot to connected sites. Client networks using affected Cisco SD-WAN platforms face immediate risk of complete network compromise.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.