The suffering of Cisco’s Catalyst SD-WAN Manager looks set to continue as the networking giant disclosed the latest in a long line of vulnerabilities.
The latest issue, tracked as CVE-2026-76504, could allow a remote, unauthenticated threat actor to access systems with admin-level privileges. Catalyst SD-WAN Manager systems exposed to the internet, with ports exposed to the internet, are at risk of exposure, the vendor confirmed.
Cisco said its Product Security Incident Response Team (PSIRT) has been aware of the exploit since September, with it only uncovered while resolving a support case.
Businesses running Catalyst SD-WAN Software earlier than version 20.9 are encouraged to upgrade, with no workaround available at present.
Cisco security teams have been fending off repeated vulnerabilities affecting Catalyst SD-WAN Manager for some time. Repeated vulnerabilities could have allowed remote attackers to bypass authentication.
With this latest issue, Cisco is encouraging customers to audit serviceproxy-access.log and vmanage-server.log files and look for any unauthorized addresses or users.
No word was given on whether breaches occurred beyond September or who, if anyone, is exploiting the flaw. Earlier issues identified in February and May were linked by Cisco's Talos security research unit to UAT-8616, a “highly sophisticated” threat actor group with evidence dating their malicious activity as far back as 2023.
Another such issue arose in June, impacting Catalyst deployments across all environments.
Comments