2026-10-02CRITICALexploitedCisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes per train
Cisco Catalyst SD-WAN Manager
product · product:cisco-catalyst-sd-wan-manager
Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Cisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector, technology · regions: switzerland
Sources cited
4
4 hosts
Action items (3)
Do-now tasks recorded on the entries about Cisco Catalyst SD-WAN Manager, newest first. Check the date before acting on an older one.
- Immediate action: Cisco confirms in-the-wild exploitation of an unauthenticated admin-level API bypass in Catalyst SD-WAN Manager and offers no workaround. Upgrade to the first fixed release of the train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1), restrict the Manager's web and API access to known trusted hosts behind a firewall in the meantime, and open a Severity 3 TAC case with the CVE id in the title for any Manager whose logs show the encoded login-path pattern.2026-10-02CVE-2026-76504
- Upgrade every Catalyst SD-WAN Manager to the first fixed release of its train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1; anything earlier than 20.9 must migrate) and, until the upgrade is done, restrict the Manager's web and API access to known trusted hosts behind a firewall.2026-10-02CVE-2026-76504
- On every Manager that was internet-reachable before the upgrade, run the compromise check described in the body and open a Severity 3 Cisco TAC case with the CVE id in the title if anything matches.2026-10-02CVE-2026-76504
Defender insights
What each entry about Cisco Catalyst SD-WAN Manager tells a defender to do, newest first.
Triage · detection
Story timeline
Hunting pivots
CVEs (exploited first)
Releases covered
Cisco Catalyst SD-WAN Manager
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-02/cve-2026-76504-cisco-catalyst-sd-wan-manager-auth-bypass-kev · ATT&CK page ↗
Entries about Cisco Catalyst SD-WAN Manager (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- cisa.gov1 (25%)
- sec.cloudapps.cisco.com1 (25%)
- security-hub.ncsc.admin.ch1 (25%)
- vulncheck.com1 (25%)
All cited sources (4)
- cisa.govCISAhttps://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
- sec.cloudapps.cisco.comCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
- security-hub.ncsc.admin.chNCSC Switzerland (Cyber Security Hub)https://security-hub.ncsc.admin.ch/#/posts/13021
- vulncheck.comVulnCheckhttps://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504