Ethical Hacking News
The U.S. CISA has added a critical flaw in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the importance of swift action to mitigate the risk of unpatched systems. The vulnerability, tracked as CVE-2026-76504, has a CVSS score of 9.8, making it a highly critical flaw that can be exploited by attackers. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability, and experts emphasize the need for organizations to prioritize the security of their networks and systems.
Cisco Catalyst SD-WAN Manager has a critical flaw (CVE-2026-76504) with a CVSS score of 9.8, making it highly critical. The vulnerability allows a remote attacker to access the system with administrator-level privileges. Cisco strongly recommends upgrading to a fixed software release to remediate the vulnerability. The impacted versions of Cisco Catalyst SD-WAN Software Release include 20.9, 20.12, and 26.1. There is no workaround for the vulnerability, but restricting internet access and placing SD-WAN control components behind a firewall can mitigate the risk. CISA has ordered federal agencies to fix the flaw by October 3rd, 2026, and recommends private organizations review the KEV catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical flaw in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the importance of swift action to mitigate the risk of unpatched systems. The vulnerability, tracked as CVE-2026-76504, has a CVSS score of 9.8, making it a highly critical flaw that can be exploited by attackers.
The vulnerability resides in Cisco Catalyst SD-WAN Manager's session authentication, allowing a remote attacker with no credentials to access the system with administrator-level privileges. This means that if an attacker can send a crafted HTTP request to the API of the affected system, they can bypass the authentication rule and gain access to the system as the admin user.
Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation of this vulnerability in September 2026. The company discovered the issue while investigating a customer support case. However, Cisco did not disclose how many customers were affected, when the attacks started, who was behind them, or what attackers did after gaining access.
In response to the vulnerability, Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability. Internet-exposed Catalyst SD-WAN Manager systems should be checked for signs of compromise, and customers should review specific log files to detect potential security issues.
The impacted versions of Cisco Catalyst SD-WAN Software Release include 20.9, 20.9.10.1, 20.12, 20.12.8.2, 20.15, 20.15.6.1, 20.18, 20.18.4.1, and 26.1. The company notes that there is no workaround for the vulnerability, but customers can restrict internet access and place SD-WAN control components behind a firewall to mitigate the risk.
CISA has ordered federal agencies to fix the flaw by October 3rd, 2026. Experts also recommend that private organizations review the KEV catalog and address the vulnerabilities in their infrastructure.
This highlights the importance of staying vigilant and proactive in terms of patching and mitigating vulnerabilities in our systems. As highlighted by the U.S. CISA, the addition of a flaw in a widely-used system like Cisco Catalyst SD-WAN Manager to the KEV catalog serves as a timely reminder to organizations to prioritize the security of their networks.
In light of this vulnerability, it is imperative to adopt a robust security posture that includes regular monitoring and analysis of system logs, implementation of secure configurations, and implementation of patch management processes to ensure that any identified vulnerabilities are addressed promptly.
The swift action taken by organizations to patch and mitigate this vulnerability can help prevent potential security breaches and minimize the risk of damage to their systems and data.
In conclusion, the recent addition of Cisco Catalyst SD-WAN Manager's flaw to the KEV catalog serves as a stark reminder of the importance of prioritizing security in our systems and networks. It highlights the need for swift action and proactive measures to mitigate the risk of unpatched systems and prevent potential security breaches.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Cisco-Catalyst-SD-WAN-Manager-Flaw-to-its-Known-Exploited-Vulnerabilities-Catalog-Highlighting-the-Need-for-Swift-Action-to-Mitigate-the-Risk-of-Unpatched-Systems-ehn.shtml
https://securityaffairs.com/200152/security/u-s-cisa-adds-cisco-catalyst-sd-wan-manager-flaw-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-76504
https://www.cvedetails.com/cve/CVE-2026-76504/
Published: Thu Oct 1 06:38:04 2026 by llama3.2 3B Q4_K_M