Skip to content

ED 26-03, Mitigate Vulnerabilities in Cisco SD-WAN Systems

In effectCISA · Emergency Directive · February 25, 2026

Summary

Required agencies to inventory Cisco Catalyst software-defined wide area network systems, collect forensic data, apply Cisco's updates, and follow CISA's hunt and hardening steps amid active exploitation.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Emergency Directive
Number
ED 26-03
Issued
February 25, 2026
Status
In effect

Still in force, possibly with amendments.

CISA issued a hunt and hardening supplemental direction the same day and a revised version (V1) with new actions and reporting on March 11, 2026.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.