Cisco Catalyst SD-WAN Manager Hit by Critical Authentication Bypass Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV). The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), allows an unauthenticated remote attacker to access an affected system with admin user privileges.
Cisco became aware of active exploitation in September 2026 and has made available indicators of compromise (IoCs) for customers to check if their environments are impacted. The company advises organizations running Catalyst SD-WAN Manager to upgrade to a fixed release as soon as possible.
Jake Knott, head of threat intelligence at watchTowr, commented that the pattern is unlikely to slow down: 'Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited vulnerabilities list... it is naturally an attractive target.'