CISA Adds Cisco Catalyst SD-WAN Manager Flaw to Known Exploited Vulnerabilities Catalog
A critical vulnerability has been discovered in Cisco's Catalyst SD-WAN Manager software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, indicating that it is being actively exploited by attackers.
The vulnerability, tracked as CVE-2026-76504, allows a remote attacker with no credentials to access the system with administrator-level privileges. This can be done by sending a crafted HTTP request to the API of the affected system, bypassing authentication rules.
Cisco's Product Security Incident Response Team learned that attackers were actively exploiting this vulnerability in September 2026. The company has not disclosed how many customers were affected or what attackers did after gaining access.