CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
thehackernews.com Oct 1, 2026

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

AI-summarised brief · reviewed before publication

The U.S. Cybersecurity and Infrastructure Security Agency added the Cisco Catalyst SD‑WAN Manager authentication bypass flaw (CVE‑2026‑76504, CVSS 9.8) to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated remote attacker to send a crafted HTTP request, bypassing authentication and gaining admin‑level access. Cisco confirmed the issue in September 2026 and released indicators of compromise for affected logs. Federal agencies must patch by October 3, 2026, and organizations are urged to upgrade immediately.

💡 Why It Matters

  • · The vulnerability exposes a critical entry point into enterprise‑wide network management, enabling attackers to control entire SD‑WAN infrastructures without credentials.
  • · Prompt remediation is essential to prevent widespread lateral movement and data exfiltration.