Cisco's CVSS 9.8 SD-WAN Manager Zero-Day Is Under Attack, and CISA Gives Agencies Until October 3
Cisco's CVSS 9.8 SD-WAN Manager Zero-Day Is Under Attack, and CISA Gives Agencies Until October 3
Cisco has confirmed that a critical vulnerability in its Catalyst SD-WAN Manager platform is being actively exploited in the wild. The flaw, tracked as CVE-2026-76504, carries a CVSS score of 9.8 out of 10, placing it among the most severe vulnerability classifications. Cisco's security advisory states that the company's Product Security Incident Response Team became aware of active exploitation in September 2026, before the vulnerability was publicly disclosed.
The urgency stems from what the flaw allows: unauthenticated remote attackers can bypass authentication entirely and obtain admin-level, or "netadmin," access to the affected systems' APIs. Security researchers who have reviewed the advisory describe this as granting essentially full administrative control without requiring any valid credentials.
How the Vulnerability Works
Cisco attributes the root cause to improper handling of URL hex, or percent, encoding, a weakness category identified as CWE-177. This type of flaw can allow specially crafted requests to slip past authentication checks that would normally block unauthorized access.
Researchers reviewing the advisory note that the vulnerability affects SD-WAN Manager deployments regardless of specific device configuration, meaning exposure is not limited to a narrow subset of setups. Cisco has released fixed software for the affected release trains. Notably, no workaround has been identified. Organizations unable to patch immediately are left with network access restriction as the only interim mitigation step, according to Cisco.
CISA's Emergency Directive and the October 3 Deadline
The Cybersecurity and Infrastructure Security Agency added CVE-2026-76504 to its Known Exploited Vulnerabilities, or KEV, Catalog on September 30, 2026, citing evidence of active exploitation. This listing triggers obligations under Binding Operational Directive 26-04, which sets vulnerability remediation requirements for Federal Civilian Executive Branch agencies.
Under that directive, federal agencies face a remediation deadline of October 3, 2026, an unusually short window that reflects the severity CISA has assigned to this vulnerability. While the directive is formally binding only on federal agencies, CISA's guidance and multiple security researchers have urged non-federal organizations, including private enterprises, to treat the same deadline as a practical benchmark given the confirmed in-the-wild exploitation.
A Pattern of Recurring SD-WAN Flaws
CVE-2026-76504 marks at least the eighth Cisco SD-WAN-related vulnerability added to CISA's KEV catalog during 2026 alone. Security researchers tracking the Catalyst SD-WAN product line point to this as part of a recurring pattern of authentication-bypass weaknesses rather than an isolated incident.
Many observers in the security research community note that the repeated emergence of similar flaw types in the same product family raises broader questions about the underlying architecture and development practices behind SD-WAN Manager's authentication mechanisms. A recurring concern voiced across security advisories is whether patching alone is sufficient, or whether organizations that were exposed during the unpatched window may already harbor undetected compromises.
What Organizations Should Do Now
Security researchers and the advisories reviewed consistently recommend the following immediate steps for any organization running Cisco Catalyst SD-WAN Manager:
- Apply Cisco's patched software releases without delay.
- Restrict network access to SD-WAN Manager interfaces as an interim measure where patching cannot happen immediately.
- Investigate systems for signs of prior compromise rather than assuming patching alone resolves any exposure that occurred during the unpatched window.
- Monitor Cisco PSIRT advisories and the CISA KEV catalog for related updates, given the pattern of recurring vulnerabilities in this product line.
Given the confirmed active exploitation, the absence of a workaround, and the short federal remediation window, security researchers broadly characterize this as a vulnerability warranting emergency-level attention rather than routine patch-cycle treatment.