Vulnerability Management

Cisco Catalyst SD-WAN Manager flaw added to CISA’s exploit list

Logo of CISCO, an American multinational digital communications technology conglomerate corporation headquartered in San Jose, California.

The Cybersecurity and Infrastructure Security Agency (CISA) added a critical CVSS 9.8 authentication bypass flaw in Cisco Catalyst SD-WAN Manager to its known exploited vulnerabilities (KEV) catalog on Sept. 30.

The bug — CVE-2026-76504 — could let an unauthenticated, remote attacker access an affected system with the privileges of the admin user because of an improper handling of URI encoding in an HTTP request.

It is the eighth new Catalyst SD-WAN Manager bug added to the KEV this year alone, according to watchTowr, which has been tracking the activity around Cisco’s SD-WAN products closely.

“Cisco SD-WAN feels like an ever-present staple of the CISA known exploited vulnerabilities list, and with eight 2026 CVEs landing on KEV this year alone, this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” said Jake Knott, head of threat intelligence at watchTowr. “None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it’s naturally an attractive target.”

Roman Sannikov, global research coordinator at iCounter, said because Cisco’s SD-WAN Manager controls how traffic moves between every branch on the network, teams need to patch quickly. But Sannikov said patching only protects against the next attempt.

“Exploitation was confirmed in September, so teams should assume someone may already have used the flaw before they upgraded,” said Sannikov.  

Randolph Barr, chief Information security officer at Cequence Security, pointed out that watchTowr's count of eight CVEs this year shows attackers (and researchers) are actively hunting this surface.

“Patching is still non-negotiable, but 'just keep patching' isn't a strategy on its own, especially when there's no workaround and exploitation is already active before most teams can even test and roll out a fix,” said Barr. “That gap is exactly where organizations get burned. What should actually change is treating internet-facing management interfaces as the crown jewels they are: restrict access to known, trusted sources, put them behind a layer that can detect and block anomalous API requests in real time, and assume a patch will always be late to at least some of your fleet.”

Jason Soroko, senior fellow at Sectigo, added that this bypass grants administrator access to the central manager’s API, creating a risk of unauthorized configuration changes across the branches it manages. Soroko said Cisco teams should patch and investigate possible compromise, also preserve logs before upgrading, check for unexpected access, and review configuration changes.

Soroko said teams should also keep management interfaces off the public internet, restrict access to approved administration systems, and send logs to a separate server. These steps follow the investigation guidance and Cisco’s hardening recommendations. Teams should also test recovery from known-good configurations.

“Installing a patch does not establish that an attacker’s access or changes have been removed,” said Soroko.

Soroko noted that Cisco has already introduced its 8000 Series Secure Routers and expanded the range in 2026 for higher-capacity networks and AI workloads. Cisco also issued SD-WAN security-hardening releases in August following an internal review.

“However, newer branch hardware does not resolve this management-software problem,” said Soroko. “The new routers can still be administered through SD-WAN Manager, which remains a system customers must protect and patch.” 

Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds