Cisco Warns of Critical Zero-Day Vulnerability in Catalyst SD-WAN Manager
Cisco has released security updates to address a critical zero-day vulnerability in its Catalyst SD-WAN Manager, which attackers are actively exploiting to gain admin privileges.
The vulnerability, tracked as CVE-2026-76504, affects all deployments of the network management software and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
This is the fifth SD-WAN zero-day vulnerability to be exploited in 2026, following a pattern of attacks that have targeted Cisco's SD-WAN products since at least 2023.