Cisco Warns of Active Exploitation of Zero-Day Vulnerability in Catalyst SD-WAN Manager
Cisco has issued an urgent security update to address a zero-day vulnerability in its Catalyst SD-WAN Manager that is already being exploited in the wild. The CVE-2026-76504 vulnerability, with a CVSS score of 9.8, allows an unauthenticated remote attacker to access an affected system with admin user privileges.
The vulnerability affects systems with exposed ports and could result in data loss, system downtime, or complete system takeover if not remediated immediately. Cisco strongly recommends that customers upgrade to a fixed software release to mitigate the risk of exploitation.
Rapid7 has urged organizations using Cisco Catalyst SD-WAN Manager to upgrade to an appropriate fixed release without waiting for a regular patch cycle, as active exploitation has already occurred. The US Cybersecurity Infrastructure and Security Agency (CISA) has added CVE-2026-76504 to its known exploited vulnerabilities catalogue.