Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Cisco has released urgent fixes for CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager that has already been exploited in the wild. The flaw affects all deployments and lets remote attackers gain admin access through crafted HTTP requests, prompting CISA to add it to the KEV catalog. #Cisco #CatalystSDWANManager #CVE202676504 #CISA #KEV

Keypoints

  • Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager.
  • The vulnerability is tracked as CVE-2026-76504 with a CVSS score of 9.8.
  • Attackers can exploit malformed HTTP requests to gain admin access.
  • All Catalyst SD-WAN Manager deployments are affected, with no workarounds available.
  • CISA added the flaw to its KEV catalog and ordered rapid patching.

Read More: https://www.securityweek.com/cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability/