Cisco has disclosed that attackers are exploiting CVE-2026-76504 in zero-day attacks against Cisco Catalyst SD-WAN Manager, an API authentication bypass that can let an attacker gain admin-level access to the network management console. The company has released fixes and IoCs, while CISA has added the flaw to its Known Exploited Vulnerabilities catalog and ordered US federal agencies to remediate it by October 3, 2026. #Cisco #CVE-2026-76504 #CiscoCatalystSD-WANManager #CISA
Keypoints
- Cisco says CVE-2026-76504 is being exploited in zero-day attacks.
- The flaw affects Cisco Catalyst SD-WAN Manager and can bypass authentication.
- Successful exploitation could give attackers admin access to the API.
- Fixed releases are available, but older versions need migration to a supported build.
- Cisco and CISA urge defenders to review logs, collect evidence, and remediate exposed systems quickly.