Government Advisory

CISA Flags Actively Exploited Flaw in Cisco Catalyst SD-WAN Manager

CISA · 30 Sept 2026
Key Takeaway If your business uses Cisco Catalyst SD-WAN Manager, check for this vulnerability and apply the vendor's patch immediately rather than waiting for a routine update cycle.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-76504, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects Cisco Catalyst SD-WAN Manager and involves a hex encoding issue that attackers are actively exploiting in the wild.

While CISA's directive requiring rapid patching applies only to US federal agencies, the agency encourages all organisations, including Australian businesses, to treat KEV-listed vulnerabilities as high priority. These flaws are known to be actively targeted by attackers, making them a common entry point for network compromise. Businesses using Cisco SD-WAN products should check whether their systems are affected and apply available patches as soon as possible.

This addition is part of CISA's ongoing effort to track vulnerabilities being exploited in real-world attacks, helping organisations worldwide prioritise their limited patching resources on the risks that matter most.

CISA Known Exploited Vulnerabilities Cisco SD-WAN vulnerability management

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.