Published Thursday, October 01, 2026 at 11:52 AM PT

<strong>CRITICAL: Cisco SD-WAN Manager Authentication Bypass—Actively Exploited Zero-Day</strong>

BLUF: Cisco has disclosed CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager allowing unauthenticated remote attackers to gain full administrative access to affected systems. The vulnerability is actively exploited in the wild. Organizations running Catalyst SD-WAN Manager must immediately: (1) inventory affected deployments, (2) check for indicators of compromise, and (3) monitor for official patches and interim mitigations from Cisco.

DETAILS

  • Vulnerability: CVE-2026-76504 — authentication bypass in Cisco Catalyst SD-WAN Manager
  • Attack Vector: Remote, unauthenticated; no special prerequisites required
  • Impact: Complete compromise — attackers gain administrative access to affected SD-WAN infrastructure
  • Status: Zero-day; Cisco has confirmed active exploitation in the wild
  • Disclosure Source: Cisco official disclosure relayed via SOC Prime threat intelligence

IMPACT

Catalyst SD-WAN Manager is a central management and control plane for Cisco’s SD-WAN fabric. Compromise of this system allows attackers to:

  • Inject malicious configurations across all connected SD-WAN edge devices
  • Intercept and redirect traffic on the SD-WAN overlay
  • Pivot into downstream enterprise networks via compromised branch connectivity
  • Establish persistent backdoors across distributed WAN infrastructure

Affected Scope: Any organization running Cisco Catalyst SD-WAN Manager in active management of SD-WAN deployments. Severity is highest for environments managing critical or sensitive traffic (finance, healthcare, government, telecommunications).

RECOMMENDED ACTIONS

  1. Immediate (Now): Isolate Catalyst SD-WAN Manager instances from untrusted networks pending patch availability; implement network segmentation restricting management console access to trusted administrative subnets only.
  2. Within 24 hours: Audit access logs and configuration change history for unauthorized administrative activity; cross-reference with exploit detection signatures from Cisco and your SOC.
  3. Ongoing: Monitor Cisco’s security advisory channels for patch release and interim guidance; apply patches immediately upon availability.
  4. Detection: Enable verbose logging on all SD-WAN Manager instances; alert on unauthenticated authentication bypass attempts and administrative account creation/privilege escalation events.

SOURCES

  • Cisco official disclosure (via SOC Prime threat intelligence feed)

Recent high-severity events at publish time:

Recent high-severity events