← Back to advisories & guidance
February 25, 2026
NSA
Advisory
Summary
The authors are aware that since 2023, at least one malicious cyber actor compromised Cisco SD-WANs via a previously unknown vulnerability, identified in late 2025 to be a zeroday exploit. This vulnerability is now patched in the latest updates from the vendor. The vulnerability allowed a malicious cyber actor to create a rogue peer joined to the network management plane, or control plane, of an organisations SD-WAN. The rogue device appears as a new but temporary, actor-controlled SD-WAN component that can conduct trusted actions within the management and control plane. The purpose of this guide is to assist organisations in investigating their Cisco SoftwareDefined Wide Area Network (SD-WAN) 1 for indicators of cyber compromise. The guide is written for cybersecurity professionals and network administrators that utilise Cisco SD-WAN All activity observed was limited to the SD-WAN components and lateral movement outside the SD-WAN was not seen by investigators.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.