Cisco Warns of Critical Zero-Day Vulnerability in Catalyst SD-WAN Manager
Cisco has released security updates to address a critical zero-day vulnerability in its Catalyst SD-WAN Manager, which attackers are actively exploiting to escalate to admin privileges.
The vulnerability, tracked as CVE-2026-76504, affects all deployments regardless of system configuration and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability, citing that the company became aware of active exploitation in September 2026.