CISA Adds Critical Cisco SD-WAN Vulnerability to Exploit List
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco's Catalyst SD-WAN Manager to its known exploited vulnerabilities catalog. The bug, CVE-2026-76504, is an authentication bypass flaw with a CVSS score of 9.8.
This is the eighth new Catalyst SD-WAN Manager bug added to the CISA list this year alone. According to watchTowr, which has been tracking activity around Cisco's SD-WAN products, this should be a clear signal that attackers have recognized the value of the platform and are unlikely to slow down.
Roman Sannikov, global research coordinator at iCounter, emphasized the importance of patching quickly because the SD-WAN Manager controls how traffic moves between every branch on the network. However, he noted that patching only protects against the next attempt, and teams should assume someone may already have used the flaw before they upgraded.
Jason Soroko, senior fellow at Sectigo, added that this bypass grants administrator access to the central manager's API, creating a risk of unauthorized configuration changes across the branches it manages. He recommended that Cisco teams patch and investigate possible compromise, preserve logs before upgrading, check for unexpected access, and review configuration changes.
Soroko also suggested that teams should keep management interfaces off the public internet, restrict access to approved administration systems, and send logs to a separate server. These steps follow the investigation guidance and Cisco's hardening recommendations. He noted that installing a patch does not establish that an attacker's access or changes have been removed.