CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

Summary

CISA has added an authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog. The critical flaw, with a CVSS score of 9.8, has been reported as actively exploited by remote attackers.

IFF Assessment

FOE

This vulnerability allows unauthenticated remote attackers to gain access to affected systems, posing a significant threat to network infrastructure.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: October 03, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating CVE-2026-76504 on Cisco Catalyst SD-WAN Manager devices immediately, given its inclusion in the KEV catalog and reports of active exploitation. This highlights the ongoing risk posed by vulnerabilities in network management infrastructure.

Read Full Story →