Interestana
Home/News/CISA Adds Exploited Cisco SD-WAN Flaw to KEV List
The Hacker News••2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

CISA Adds Exploited Cisco SD-WAN Flaw to KEV List

CISA Adds Exploited Cisco SD-WAN Flaw to KEV List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday. This addition follows credible reports indicating that the vulnerability is currently being actively exploited in the wild. The flaw, identified by the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-76504, carries a high severity rating with a CVSS score of 9.8 out of a possible 10. This critical score signifies that the vulnerability is extremely easy to exploit and can have a significant impact on affected systems. Specifically, the authentication bypass vulnerability could enable an unauthenticated attacker, operating remotely, to gain unauthorized access to an affected Cisco Catalyst SD-WAN Manager system. The implications of such unauthorized access are substantial, potentially allowing an attacker to control network devices, exfiltrate sensitive network configuration data, or disrupt network operations. Cisco Catalyst SD-WAN Manager is a key component for managing and orchestrating software-defined wide area networks (SD-WAN), which are crucial for modern enterprise network infrastructure, enabling centralized control and optimization of network traffic across distributed locations. The inclusion of CVE-2026-76504 on the KEV list mandates that all U.S. federal civilian executive branch agencies must implement protective measures against this vulnerability by a specified deadline, which is typically within a set number of days from the addition date. This directive aims to mitigate the risk of these agencies falling victim to attacks leveraging this known exploited flaw. While the specific details of the active exploitation, such as the threat actors involved or the exact methods used, were not disclosed by CISA, the agency's action underscores the immediate threat posed by this vulnerability. Organizations utilizing Cisco Catalyst SD-WAN Manager are strongly advised to review their security posture, apply any available patches or workarounds provided by Cisco, and enhance their network monitoring capabilities to detect any signs of compromise. The KEV catalog serves as a critical resource for cybersecurity professionals, highlighting vulnerabilities that pose the most significant and immediate risks to U.S. networks and critical infrastructure, thereby prioritizing patching and mitigation efforts.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next