Cisco's Catalyst SD-WAN Manager Hit by Another Critical Vulnerability
Cisco's Catalyst SD-WAN Manager has been plagued by a series of vulnerabilities, and the latest issue is no exception. The networking giant disclosed a new flaw, tracked as CVE-2026-76504, which could allow remote, unauthenticated attackers to access systems with admin-level privileges.
The vulnerability affects Catalyst SD-WAN Manager systems exposed to the internet, particularly those with ports exposed to the internet. Cisco's Product Security Incident Response Team (PSIRT) has been aware of the exploit since September, but it was only discovered while resolving a support case.
Cisco is encouraging customers running Catalyst SD-WAN Software earlier than version 20.9 to upgrade, as there is no available workaround for this issue. In addition, businesses are advised to audit serviceproxy-access.log and vmanage-server.log files for any unauthorized addresses or users.