Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco warns of new SD-WAN zero-day exploited in attacks

CISA added CVE-2026-76504 (Cisco Catalyst SD-WAN Manager) to its Known Exploited Vulnerabilities catalog on September 30, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI…

Excerpt from the primary source: CISA Known Exploited Vulnerabilities

Who is affected

Enterprises · Developers · Security professionals

Affected technology: Catalyst SD-WAN Manager, Cisco networking & security

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Catalyst SD-WAN Manager systems are exposed to active attacks now.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Act now

Treat this as an emergency. Identify every system running Cisco networking & security and Catalyst SD-WAN Manager, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.

CISA's required action for CVE-2026-76504: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines." US federal civilian agencies must comply by October 3, 2026.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (CVE-2026-76504) is being actively exploited, CISA warns CISA Known Exploited Vulnerabilities · cisa.gov · Sep 30, 2026 · Primary source
CISA Adds One Known Exploited Vulnerability to Catalog CISA Cybersecurity Advisories · cisa.gov · Sep 30, 2026

Original reporting

Cisco warns of new SD-WAN zero-day exploited in attacks BleepingComputer · bleepingcomputer.com · Sep 30, 2026

Additional reporting

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability SecurityWeek · securityweek.com · Oct 1, 2026
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV The Hacker News · thehackernews.com · Oct 1, 2026
Severity: ElevatedAction: Be aware

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

Severity: ElevatedAction: Be aware

The Closed Quorum: Inside the first reported autonomous AI C2 implant

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460) is being actively exploited, CISA warns

CISA added CVE-2026-76460 (Cisco Identity Services Engine) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Identity Services Engine systems are exposed to active attacks now.

Act now

Treat this as an emergency.