Cisco warns of new SD-WAN zero-day exploited in attacks
CISA added CVE-2026-76504 (Cisco Catalyst SD-WAN Manager) to its Known Exploited Vulnerabilities catalog on September 30, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI…
CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Catalyst SD-WAN Manager systems are exposed to active attacks now.
Treat this as an emergency.
