CyberzSOC

Publication detail
← Back to advisories & guidance

Cisco SD-WAN Threat Hunt Guide ↗ source

February 25, 2026 NSA Advisory

Summary

The authors are aware that since 2023, at least one malicious cyber actor compromised Cisco SD-WANs via a previously unknown vulnerability, identified in late 2025 to be a zeroday exploit. This vulnerability is now patched in the latest updates from the vendor. The vulnerability allowed a malicious cyber actor to create a rogue peer joined to the network management plane, or control plane, of an organisations SD-WAN. The rogue device appears as a new but temporary, actor-controlled SD-WAN component that can conduct trusted actions within the management and control plane. The purpose of this guide is to assist organisations in investigating their Cisco SoftwareDefined Wide Area Network (SD-WAN) 1 for indicators of cyber compromise. The guide is written for cybersecurity professionals and network administrators that utilise Cisco SD-WAN All activity observed was limited to the SD-WAN components and lateral movement outside the SD-WAN was not seen by investigators.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2022-20775 7.8 High Cisco SD-WAN Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper ac…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.