Cisco Patches Exploited Catalyst SD-WAN Zero-Day
Cisco released urgent patches for a critical authentication bypass, CVE-2026-76504 (CVSS 9.8), in Catalyst SD-WAN Manager that lets unauthenticated attackers gain admin API access. The flaw is already exploited in the wild, and CISA added it to its KEV catalog, ordering federal agencies to patch within three days.
- CVE-2026-76504 carries a CVSS score of 9.8 and affects all Catalyst SD-WAN Manager configurations
- Fixes shipped in versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1
- CISA added the flaw to its KEV catalog, giving federal agencies three days to patch
- No workarounds exist; Cisco published indicators of compromise
Read next
Security