CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- ID
- 30718
- Status
- summarized
- Published
- 01 Oct 2026, 6:33 PM
- Fetched
- 01 Oct 2026, 8:10 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 01 Oct 2026, 8:11 PM
- Tags
- Audience
- developers
What happened
CISA added CVE-2026-76504, a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog on Wednesday after Cisco confirmed active exploitation in September 2026. The flaw is a hex/URI-encoding handling bug: a crafted HTTP request to the API lets an unauthenticated remote attacker act as the admin user. Cisco published IoCs but not victim counts or attribution, and U.S. federal civilian agencies had until October 3, 2026 to patch — a two-day window. watchTowr's Jake Knott noted eight Cisco SD-WAN CVEs have hit KEV in 2026 alone.
Why it matters
If you or a client run Cisco Catalyst SD-WAN Manager, this is a same-day patch plus log check: grep /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check calls from unknown IPs and for usernames starting with 'viptela-reserved-'. If you don't run that appliance, nothing here changes your week — it is enterprise network gear, not developer tooling, and the useful signal is the pattern (eight SD-WAN CVEs on KEV this year) for anyone doing MSP or enterprise infra work.
Discussion angle
The FCEB patch deadline was two days from KEV listing — is a 48-hour federal patch window realistic for enterprise network appliances, and does an encoding-normalization bug (URI/hex handling) in an API auth path point at a class of bug your own API gateway might share?