Security advisories

Cisco Catalyst SD-WAN Manager Zero-Day Vulnerability (CVE-2026-76504)

October 1, 2026

3 MINS READ

THE THREAT

On September 30th, 2026, Cisco disclosed a critical zero-day vulnerability, CVE-2026-76504 (CVSS: 9.8), affecting Cisco Catalyst SD-WAN Manager. Cisco has confirmed active exploitation of this vulnerability in the wild, and CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of October 3rd, 2026.

Successful exploitation could allow an unauthenticated, remote attacker to gain administrator access to the SD-WAN Manager, which centrally controls the SD-WAN environment. As exploitation is ongoing, organizations running affected Cisco Catalyst SD-WAN Manager deployments are advised to apply the relevant patches immediately.

What we're doing about it

What you should do about it

Additional information

CVE-2026-76504 is a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. It could allow an unauthenticated remote attacker to access an affected system with privileges of the admin user. Threat actors can exploit this vulnerability by sending a crafted request to the affected system's API.

Cisco's Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026, but details on the threat actor, the number of affected organizations, and when exploitation began have not been shared.

Cisco notes that systems exposed to the internet are at greatest risk of compromise. Because the log indicators published by Cisco can also appear during normal operations, they should be assessed against the organization's normal network posture to avoid false positives.

Cisco has also addressed this vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605. No user action is required for Cisco-managed cloud deployments. Edge and network management platforms such as SD-WAN Manager are high-value targets because they provide centralized control over network infrastructure. Given the confirmed exploitation and the KEV listing, affected organizations should treat patching and compromise assessment as an immediate priority.

Product Name Affected Version(s) Resolved Version(s)
Cisco Catalyst SD-WAN ManagerEarlier than 20.9Migrate to a fixed release
20.920.9.10.1
20.1220.12.8.2
20.1520.15.6.1
20.1820.18.4.1
26.126.1.2.1
26.226.2.1

References:

[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
[2] https://nvd.nist.gov/vuln/detail/cve-2026-76504
[3] https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories