HighII Cyber Warfare & Critical Infrastructure30 September 2026, Wednesday
Exploited flaw in Cisco's SD-WAN management console joins CISA catalogue
Cisco said on 30 September that CVE-2026-76504, a flaw rated 9.8 in Catalyst SD-WAN Manager, was being used in attacks. CISA added it to its list of exploited vulnerabilities the same day. There is no workaround, only an update.
According to a Rapid7 assessment of 30 September, the flaw scored 9.8 out of 10 on the CVSS scale. The bug stems from the system mishandling URL encoding. A remote attacker without credentials can bypass authentication with a single crafted HTTP request and gain administrator rights on the API. SD-WAN Manager is the central console for software-defined networks that link branch sites, so its compromise can affect the whole network.
According to The Hacker News, Cisco noticed the exploitation during a technical support case in September. The company released patches for versions 20.9, 20.12, 20.15, 20.18, 26.1 and 26.2; versions older than 20.9 must be migrated. The report says 8 Cisco SD-WAN flaws have entered the CISA catalogue in 2026. Rapid7 writes that this is the 5th zero-day exploited in the SD-WAN product since the start of the year. Cisco did not disclose the number of affected customers and did not attribute the attacker to any group.
CISA's Known Exploited Vulnerabilities (KEV) catalogue listed the flaw as of 30 September. The catalogue obliges US federal agencies to patch within a set period. The same catalogue added 2 Citrix NetScaler flaws on 27 September and an Apple CoreGraphics flaw on 29 September, so at least 4 new entries have been listed in the past 4 days.
Talay assessment
Bottom line
Network management consoles remain a priority target because they give attackers access to the whole network through a single door. A 5th zero-day this year in the same product family shows that new bypasses are found quickly behind each patch. With neither the attacker nor the number of affected organisations disclosed, the scale of the incident should become clearer in the coming days.
Likely effects
- Enterprise network securityNegativeWeeks
With no workaround, organisations that expose SD-WAN Manager to the internet must upgrade without waiting for their maintenance schedule.
- Critical infrastructureNegative1–6 months
Compromise of consoles that link branches and sites creates a risk that network traffic is redirected in multi-site sectors such as energy and finance.
- Organisations in TürkiyeUncertainWeeks
Turkish banks, telecoms operators and public bodies that use Cisco SD-WAN must also check their patch status against the same version list. No exploitation specific to Türkiye has been reported.
Possibilities, ranked
- 1Exploitation spreads50%
As technical details circulate, mass scanning of unpatched systems and new breach reports follow.
Watch: Scanning and breach reports on CVE-2026-76504 from security firms
- 2Limited targeted attacks35%
Exploitation stays limited to a small number of targets and patches are applied quickly.
Watch: An update on customer impact in Cisco's advisory
- 3Link to a state-backed group15%
The exploitation is attributed to a known state-backed group that targets network devices.
Watch: Attacker attribution from Cisco Talos or CISA
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- CVSS score▼ 9.8
- Cisco SD-WAN flaws added to KEV in 2026▼ 8
- New KEV entries in the past 4 days▼ 4