Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

CVE‑2026‑76504 Cisco Catalyst SD‑WAN Manager Hex Encoding Vulnerability Added to CISA KEV Catalog

CISA has placed CVE‑2026‑76504, a remote‑code‑execution flaw in Cisco Catalyst SD‑WAN Manager, into its Known Exploited Vulnerabilities catalog, signaling active exploitation and urging rapid remediation. The addition highlights the importance of robust vulnerability‑management controls for audit readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

CVE‑2026‑76504 Cisco Catalyst SD‑WAN Manager Hex Encoding Vulnerability Added to CISA KEV Catalog

What It Is – CISA has listed CVE‑2026‑76504, a hex‑encoding flaw in Cisco Catalyst SD‑WAN Manager, in its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability allows an attacker who can send specially‑crafted data to execute arbitrary code on the management interface.

Exploitability – Active exploitation has been confirmed by CISA; the vulnerability is publicly disclosed and classified as high‑risk for federal networks.

Affected Products – Cisco Catalyst SD‑WAN Manager (all versions vulnerable to the hex‑encoding flaw).

Why It Matters for Trust & Control Assurance

  • Vulnerability‑management control – Demonstrates the need for continuous monitoring of CVE feeds and rapid patching to satisfy the control objective of “maintain an up‑to‑date vulnerability remediation program.”
  • Audit‑ready evidence – Remediation actions (patch deployment, validation scans) must be captured as immutable evidence to support compliance audits and federal directives (e.g., BOD 26‑04).
  • Defensible risk posture – Prioritizing KEV‑listed flaws shows due‑diligence to stakeholders and reduces the likelihood of a breach that would erode trust in the organization’s security program.

Recommended Actions

  • Verify whether any Cisco Catalyst SD‑WAN Manager instances in your environment are vulnerable to CVE‑2026‑76504.
  • Apply Cisco’s remediation patch immediately and document the change in your vulnerability‑management system.
  • Update your risk‑based remediation schedule to prioritize all KEV‑catalog items, and retain evidence of patch verification for audit purposes.

Source: CISA Alert – Known Exploited Vulnerability Catalog

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →