Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Auth Bypass (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager Actively Exploited, Added to CISA KEV

CISA has added CVE‑2026‑76504, a critical authentication‑bypass flaw in Cisco Catalyst SD‑WAN Manager, to its Known Exploited Vulnerabilities list after confirming active attacks. Organizations must patch promptly and demonstrate control‑level evidence for audit readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Critical Authentication Bypass (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager Actively Exploited, Added to CISA KEV

What It Is — A critical authentication‑bypass flaw (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager allows an unauthenticated remote attacker to gain full administrative access to the management console.

Exploitability — The vulnerability is confirmed to be actively exploited in the wild; CISA has placed it in the Known Exploited Vulnerabilities (KEV) catalog. CVSS 9.8 (Critical).

Affected Products — Cisco Catalyst SD‑WAN Manager (all supported versions prior to the vendor‑released patch).

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous monitoring of authentication controls on network‑infrastructure assets.
  • Demonstrates that timely patch management is a core piece of audit‑ready evidence for any control framework.
  • Provides a concrete example of how a single control gap can affect multiple compliance regimes, underscoring the value of a unified control‑mapping approach.

Recommended Actions

  • Deploy Cisco’s security patch for CVE‑2026‑76504 immediately.
  • Verify the firmware version on all SD‑WAN Manager instances against the patch baseline.
  • Integrate automated vulnerability scanning for network devices into your continuous monitoring program.
  • Capture remediation evidence (patch logs, configuration snapshots) to support audit readiness.

Source: The Hacker News – CISA Adds Exploited Cisco Catalyst SD‑WAN Manager Auth Bypass to KEV

📰 Original Source
https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →