Cisco Patches a Critical Network Flaw That Attackers Are Already Using

Cisco has released fixed software for a flaw in Catalyst SD-WAN Manager that its own product security team says is being exploited. The U.S. Cybersecurity and Infrastructure Security Agency added the same flaw to its catalog of exploited vulnerabilities the same day, Sept. 30, 2026.
Catalyst SD-WAN Manager is the console network teams use to configure and monitor large fleets of routers and other devices. Cisco's advisory says the flaw, tracked as CVE-2026-76504, could let a remote attacker who has not logged in reach the system's programming interface with the privileges of the admin user, the account that controls the console.
Cisco rates it 9.8 out of a possible 10 on the standard industry severity scale, labels it critical, and says it affects Catalyst SD-WAN Manager regardless of how the system is configured. There is no workaround; upgrading is the only fix. The first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1, and anything on a release earlier than 20.9 has to be migrated. The cloud-managed version of the service has already been fixed and needs no customer action. For on-premises deployments, restricting access to the console from the internet reduces exposure but does not remove the flaw.
CISA listed the identifier on evidence of active exploitation, and says Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of exploited flaws on publicly exposed systems that would hand an attacker total control. The directive also sets expectations for checking whether a system was compromised before the patch was applied. It binds federal agencies only, and CISA encourages every other organization to work the same way.
Cisco says the vulnerability was found while its support engineers were resolving a customer case.
