Cisco warns of actively exploited zero-day in SD-WAN Manager API
Cisco disclosed on September 30 that attackers are actively exploiting a critical zero-day vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager. The flaw, which has a CVSS score of 9.8, allows an unauthenticated attacker with network access to the Manager's API to gain full administrative privileges. Cisco has released patched software versions for several release trains but states there are no workarounds, advising customers to restrict network access until systems are upgraded. The vulnerability affects all on-premises deployments of the software, particularly those exposed to the internet, regardless of their configuration.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in