Cisco SD-WAN Solution Hit by Fifth Zero-Day Attack This Year
Cisco has revealed that its SD-WAN solution has been exploited in zero-day attacks for the fifth time this year. The vulnerability, CVE-2026-76504, affects Cisco Catalyst SD-WAN Manager and can give attackers control over the network.
The vendor's incident responders became aware of active exploitation of the vulnerability in September 2026 after receiving a support case from a customer.
Cisco has provided indicators of compromise for defenders to look out for, including entries in specific log files. However, the company notes that these indicators may also occur during standard operations and must be assessed against normal network posture to avoid false positives.