Critical Authentication Bypass (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager Actively Exploited, Added to CISA KEV
What It Is — A critical authentication‑bypass flaw (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager allows an unauthenticated remote attacker to gain full administrative access to the management console.
Exploitability — The vulnerability is confirmed to be actively exploited in the wild; CISA has placed it in the Known Exploited Vulnerabilities (KEV) catalog. CVSS 9.8 (Critical).
Affected Products — Cisco Catalyst SD‑WAN Manager (all supported versions prior to the vendor‑released patch).
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous monitoring of authentication controls on network‑infrastructure assets.
- Demonstrates that timely patch management is a core piece of audit‑ready evidence for any control framework.
- Provides a concrete example of how a single control gap can affect multiple compliance regimes, underscoring the value of a unified control‑mapping approach.
Recommended Actions
- Deploy Cisco’s security patch for CVE‑2026‑76504 immediately.
- Verify the firmware version on all SD‑WAN Manager instances against the patch baseline.
- Integrate automated vulnerability scanning for network devices into your continuous monitoring program.
- Capture remediation evidence (patch logs, configuration snapshots) to support audit readiness.
Source: The Hacker News – CISA Adds Exploited Cisco Catalyst SD‑WAN Manager Auth Bypass to KEV