CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Summary
CISA has added an authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog. The critical flaw, with a CVSS score of 9.8, has been reported as actively exploited by remote attackers.
IFF Assessment
This vulnerability allows unauthenticated remote attackers to gain access to affected systems, posing a significant threat to network infrastructure.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: October 03, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or mitigating CVE-2026-76504 on Cisco Catalyst SD-WAN Manager devices immediately, given its inclusion in the KEV catalog and reports of active exploitation. This highlights the ongoing risk posed by vulnerabilities in network management infrastructure.