If your business runs on SD-WAN, this is the week to pay attention.
For the past several months, security researchers have been tracking an active, ongoing attack campaign against Cisco’s Catalyst SD-WAN platform. Cisco is one of the most widely deployed SD-WAN systems in the country. Seven separate vulnerabilities in this product line have been exploited in the wild in 2026 alone, and the pace isn’t slowing down. Two of them scored a perfect 10 out of 10 on severity. CISA has issued warnings. Government agencies and critical infrastructure providers have already been hit.
Why this matters to you, even if you’re not “critical infrastructure.”
A sophisticated threat group has been chaining these vulnerabilities together to gain root-level access to SD-WAN controllers and managers. These are the devices that sit at the center of a company’s network and decide how traffic moves between locations. Once inside, attackers have deployed web shells, manipulated configuration files, and covered their tracks by selectively deleting and restoring logs. In one documented case, a threat actor targeted a service provider’s SD-WAN infrastructure specifically because compromising one provider gives access to every downstream customer network riding on it.
Schedule Meeting
That’s the part business owners should sit with. This isn’t just “a Cisco problem.” If your IT provider, carrier, or MSP is running SD-WAN infrastructure on your behalf, a vulnerability in their equipment can become your outage, your breach, or your compliance headache — without you ever touching a keyboard.
What’s actually going on, in plain terms:
-
- Attackers are chaining multiple flaws together: an authentication bypass to get in, then a privilege-escalation bug to take full control.
- Patches have lagged behind exploitation — several of these vulnerabilities were being actively used against real networks months before Cisco issued a fix.
- The attack surface isn’t huge (researchers estimate somewhere in the range of 500 exposed instances), but the accounts being targeted skew toward large enterprises, government, and critical infrastructure — meaning attackers are picking high-value targets on purpose, not spraying and praying.
- This follows the same edge-device playbook used in the 2024 Salt Typhoon campaign against telecom carriers — attackers know that routers and SD-WAN controllers are a soft, high-leverage target most companies aren’t watching closely.
What we’d tell any client asking about this right now:
-
- Ask your provider directly which SD-WAN platform you’re on and whether it’s patched. Don’t assume, confirm.
- Get an inventory of anything internet-facing. SD-WAN managers and controllers should never be reachable from the open internet unless there’s a very specific, well-guarded reason.
- Review admin account access. Several of these exploits required an authenticated session to escalate from. Fewer standing admin credentials means fewer doors for an attacker to walk through.
- Ask what your redundancy looks like if your primary SD-WAN provider has an incident. This is exactly the kind of single-point-of-failure question that gets skipped until it’s too late.
This is the exact reason we don’t sell one carrier’s box and call it a day.
Agility isn’t tied to a single manufacturer or a single carrier’s roadmap. When something like this hits the headlines, our job is to look at what you’re actually running. We tell you honestly whether you’re exposed, and if it makes sense to get you options from across our carrier relationships instead of leaving you stuck waiting on one vendor’s patch cycle. That’s the whole point of working with an independent broker instead of buying direct: someone is watching your interests, not the carrier’s.
If you’re not sure what SD-WAN platform is sitting behind your network right now, that’s a five-minute conversation worth having. Reach out and we’ll help you find out.
Sources: Cybersecurity Dive, SecurityWeek, Google Cloud (Mandiant) Threat Intelligence, Cloud Security Alliance, NetworkTigers Weekly Roundup July 2026.







