Wednesday, September 30, 2026 Newsletter Advertise
Breaking
Advisories

BreakingCisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being actively exploited, CISA warns

CISA added the Cisco Catalyst SD-WAN Manager vulnerability to its Known Exploited Vulnerabilities catalog on September 30, 2026, with a federal remediation deadline of October 3, 2026.

CVE-2026-76504, CVSS 9.8 Critical, US federal deadline October 3, 2026, CISA KEV

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504, a Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. CISA adds a flaw to the catalog when it has reliable evidence that attackers are exploiting it in the wild.

What CISA says

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

— CISA KEV catalog entry for CVE-2026-76504

Key facts

CVE CVE-2026-76504
Vendor / product Cisco Catalyst SD-WAN Manager
Added to KEV September 30, 2026
Federal deadline October 3, 2026
Known ransomware use Unknown
Weakness (CWE) CWE-177
CISA forensic triage Yes
CVSS base score (NVD) 9.8 Critical
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Who has to act, and by when

US federal civilian executive branch agencies are required to remediate the vulnerability by October 3, 2026. CISA urges all organizations to prioritize KEV-listed flaws as part of their vulnerability management.

CISA’s required action for this entry:

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Advisories