Critical Cisco SD-WAN Flaw Under Active Attack: Patch Now
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities list after confirming it is being actively exploited. The vulnerability, CVE-2026-76504, carries a near-maximum severity score of 9.8 out of 10. It stems from improper handling of URI encoding in HTTP requests, which allows an unauthenticated attacker to send a crafted request and gain admin-level access to the system's API without needing any login credentials.
Cisco confirmed it became aware of active exploitation in September 2026 but has not disclosed who is behind the attacks, how many organisations have been affected, or when exploitation first began. The company has released indicators of compromise that administrators can check in specific log files to see if their systems have been targeted. US federal agencies have been given until 3 October 2026 to apply fixes.
Security researchers note that Cisco SD-WAN products have been a recurring target this year, with eight separate vulnerabilities in the platform added to CISA's exploited list during 2026 alone. Because SD-WAN Manager acts as a central control point for managing large networks, it remains a highly attractive target for attackers seeking broad access with a single successful exploit.