Cybersecurity · October 1, 2026
Cisco has confirmed that attackers are actively exploiting a critical zero-day, tracked as CVE-2026-76504, in its Catalyst SD-WAN Manager platform. The flaw lets an unauthenticated remote attacker call the Manager's administrative API without ever logging in, effectively handing over full control of the SD-WAN deployment. Cisco has shipped fixed releases but says no workaround exists, so organizations running SD-WAN Manager should patch immediately.
// source: thehackernews.com ↗