Skip to content
See the World Through ScienceA project of ALLATRA

Cisco Patches a Critical Network Flaw That Attackers Are Already Using

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Colored Ethernet patch cables plugged into the front ports of a rack-mounted Cisco Catalyst network switch.
Patch cords land on the front ports of a Cisco Catalyst access switch, the class of equipment a fleet console such as Catalyst SD-WAN Manager configures (illustrative)."Too many cables" by KIUI staff, via flickr, CC-BY-2.0

Cisco has released fixed software for a flaw in Catalyst SD-WAN Manager that its own product security team says is being exploited. The U.S. Cybersecurity and Infrastructure Security Agency added the same flaw to its catalog of exploited vulnerabilities the same day, Sept. 30, 2026.

Catalyst SD-WAN Manager is the console network teams use to configure and monitor large fleets of routers and other devices. Cisco's advisory says the flaw, tracked as CVE-2026-76504, could let a remote attacker who has not logged in reach the system's programming interface with the privileges of the admin user, the account that controls the console.

Cisco rates it 9.8 out of a possible 10 on the standard industry severity scale, labels it critical, and says it affects Catalyst SD-WAN Manager regardless of how the system is configured. There is no workaround; upgrading is the only fix. The first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1, and anything on a release earlier than 20.9 has to be migrated. The cloud-managed version of the service has already been fixed and needs no customer action. For on-premises deployments, restricting access to the console from the internet reduces exposure but does not remove the flaw.

CISA listed the identifier on evidence of active exploitation, and says Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of exploited flaws on publicly exposed systems that would hand an attacker total control. The directive also sets expectations for checking whether a system was compromised before the patch was applied. It binds federal agencies only, and CISA encourages every other organization to work the same way.

Cisco says the vulnerability was found while its support engineers were resolving a customer case.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Cisco Patches a Critical Network Flaw That Attackers Are Already Using

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.