“strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” Cisco wrote on September 30, as it moved to plug a critical zero-day in its Catalyst SD-WAN Manager that is already being exploited in the wild.
Cisco advisory (Sept. 30) and the immediate warning
On September 30, Cisco published a security advisory for CVE-2026-76504, a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. Cisco characterized the flaw as critical, assigning it a CVSS score of 9.8, and warned that an unauthenticated, remote attacker could gain access to an affected system with the privileges of the admin user. The company advised customers to upgrade to a fixed software release and noted there are no workarounds that remediate the vulnerability without applying the security update.
CVE-2026-76504: how the flaw works
According to Cisco, the vulnerability stems from improper handling of URI encoding in an HTTP request. A crafted HTTP request can bypass authentication rules and give an attacker access to the API with administrator permissions. With administrative API access, an attacker could “compromise the whole network,” pivot through connected systems, and “alter and delete files and backups,” creating risks that Cisco said include data loss, system downtime, or complete system takeover.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildActive exploitation, Rapid7 and CISA response
Cisco reported that CVE-2026-76504 is already under “active exploitation.” Security firm Rapid7 echoed the urgency in a blog post on October 1, urging organizations that use Cisco Catalyst SD-WAN Manager to upgrade immediately and to audit affected systems for compromise because active exploitation has occurred. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog and recommended organizations apply mitigations.
Mitigation deployed to Cisco Catalyst SD-WAN Cloud Hosted environments, but apply patches
Cisco has deployed a mitigation to Cisco Catalyst SD-WAN Cloud Hosted environments and said that the mitigation was “proven successful in a test environment.” At the same time, Cisco warned customers to determine the applicability and effectiveness of that mitigation “in their own environment and under their own use conditions.” The advisory makes clear that, beyond the cloud-hosted mitigation, the vendor’s recommended fix is upgrading to a fixed software release—there is no alternative workaround that fully remediates the vulnerability without applying the update.
What this means for technologists, enterprise security teams, and procurement leaders
- Technologists and security teams: Audit any Cisco Catalyst SD-WAN Manager instances, especially those with ports exposed to the internet, and prioritize upgrade to the fixed release. Rapid7’s advisory explicitly urged auditing for compromise because the flaw has seen active exploitation.
- Enterprise security teams and CISOs: Treat public-facing SD-WAN Manager interfaces as high risk. The combination of administrator-level API access and the potential to pivot and delete backups elevates this issue from a single-product patch to an enterprise continuity and recovery concern.
- Procurement leaders and cloud operators: Note that Cisco has already pushed a mitigation to its Cloud Hosted SD-WAN environments, but Cisco’s own advisory directs customers to evaluate that mitigation in their own operational context and to apply the vendor’s fixed software release where required.
Cisco’s advisory follows closely on last month’s warning about active exploitation of CVE-2026-76460 affecting Cisco Identity Services Engine (ISE), underscoring a rapid sequence of high-severity disclosures for Cisco products. With CVE-2026-76504 carrying a 9.8 score, no workaround available, and documented active exploitation, the practical answer Cisco and security firms have given is simple and stark: upgrade now, and audit systems for signs of compromise.
The immediate technical fix is clear; the harder test is operational: whether organizations with internet-exposed Catalyst SD-WAN Manager systems have the patch window and the forensic capacity to both apply the fixed release and discover any intrusions that may already have occurred.
https://www.infosecurity-magazine.com/news/critical-cisco-catalyst-sdwan/




