Who is affected
Cisco Catalyst SD-WAN Manager is affected by this vulnerability. The flaw permits unauthenticated remote access to the system with admin privileges through improper handling of URI encoding in HTTP requests. The record does not specify which versions are vulnerable, the scope of deployments most at risk, or whether cloud-hosted and on-premises instances are both affected.
How to check whether this touches you
- Inventory: do you operate Cisco Catalyst SD-WAN Manager in your environment, either as an appliance or cloud service?
- Reachability: is the management interface reachable from the internet or from untrusted networks without VPN or IP allowlisting?
- Version check: retrieve the running version from the system administration console or API; version identification alone is a signal only, as backported fixes may exist in patches that do not increment the minor version.
- Log inspection: search authentication logs for admin user sessions originating from unexpected source IPs or without corresponding login events, especially in the weeks before you became aware of this issue.
What to do
- Immediately restrict network access to the Catalyst SD-WAN Manager interface to trusted administrative networks only, using firewall rules, VPN enforcement, or IP allowlisting.
- Check Cisco's security advisories and release notes for the patched version applicable to your running release; apply the patch according to your maintenance window if one is available.
- If a patch is unavailable for your version, evaluate whether discontinuation of the product or migration to an alternative is feasible within your compliance deadline (federal remediation due date is 2026-10-03).
- Enable and retain authentication and access logs at the highest verbosity available; ensure logs cover at least 90 days of history.
- If internet-facing, notify your CISO and incident response team; escalate to your organisation's vulnerability management or security operations centre for prioritisation.
If you find you were exposed
Exploitation of unauthenticated admin access typically occurs before public disclosure, so you should search authentication logs and system audit trails backwards from the present date for admin sessions without a corresponding login event or with suspicious timestamps. Log retention is your primary constraint; if logs have been rotated or deleted, conduct a file-system forensic review of the Catalyst SD-WAN Manager appliance to check for evidence of unauthorised configuration changes or data exfiltration. Document all findings for regulatory reporting if required.