INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cisco SD-WAN Manager Vulnerable to Critical Authentication Bypass
| 2026-09-30 14:46 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A critical vulnerability has been identified in Cisco SD-WAN Cloud-Pro and Cisco SD-WAN for Government, two deployment types previously mentioned. The flaw, CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as an admin user, carrying a CVSS score of 9.8 out of 10. This vulnerability affects multiple release trains, including 20.15 and later versions, but is already fixed in release 20.15.605 for Cisco SD-WAN Cloud (Cisco Managed). Customers on affected releases are advised to open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title to help determine whether their Manager has been compromised.
Technical Mitigations AI-generated
• Restrict access to the SD-WAN Manager from unsecured networks such as the internet.
• Only allow known, trusted hosts in when internet access is required and sit control components behind a firewall.
• For on-prem Managers exposed to the internet, restrict access to it.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.log
vm•••••.log
20.15.•••.•••
20.9.•••.•••
20.12.•••.•••
20.18.•••.•••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-76504CVE-2026-76504
CVE-2026-20262CVE-2026-20262
CVE-2026-20127CVE-2026-20127
CVE-2026-20182CVE-2026-20182
CVE-2026-20245CVE-2026-20245
Target & Sectors
Global Scope
Incident Timeline
November 2021
Threat actors have exploited 90 Cisco vulnerabilities, including four in Cisco Catalyst SD-WAN Manager and seven associated with ransomware operations, since November 2021.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, CISA has
tagged 90 Cisco vulnerabilities
as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.
general_metric
90 Cisco vulnerabilities
Since November 2021, CISA has
tagged 90 Cisco vulnerabilities
as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.
at least 2023
Threat actors exploited a maximum-severity Catalyst SD-WAN Controller auth bypass flaw (CVE-2026-20182) since at least 2023, while Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127).
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20182
Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February,
exploited
since at least 2023, and tagged a
maximum-severity Catalyst SD-WAN Controller auth bypass flaw
(CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.
vulnerability
CVE-2026-20127
Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February,
exploited
since at least 2023, and tagged a
maximum-severity Catalyst SD-WAN Controller auth bypass flaw
(CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.
organisation
Catalyst SD-WAN Controller
Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February,
exploited
since at least 2023, and tagged a
maximum-severity Catalyst SD-WAN Controller auth bypass flaw
(CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.
September 2026
The Cisco Product Security Incident Response Team became aware of active exploitation of a vulnerability in its SD-WAN product in September 2026.
Click on any entity below to view its context and source!
organisation
Product Security Incident Response Team
Cisco said its Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in September 2026.
September 30
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager.
Click on any entity below to view its context and source!
organisation
Cisco SD-WAN
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an
advisory
on September 30.
organisation
Cisco
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an
advisory
on September 30.
tactic
T1588.006 - Vulnerabilities
As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026.
2026/09/30
Threat actors exploited CVE-2026-76504, a vulnerability in T1588.006 protocol, to target U.S. federal agencies.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-76504
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
tactic
T1588.006 - Vulnerabilities
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
attribution
Known Exploited
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
attribution
KEV
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
2026/09/30
Threat actors are actively exploiting CVE-2026-76504, a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager's API session-based authentication management.
Click on any entity below to view its context and source!
organisation
API
The flaw,
CVE-2026-76504
, could allow a remote attacker with no login access to use the Manager's API as the admin user.
"
The CVE-2026-76504 vulnerability affects all deployments regardless of system configuration, was found in API session-based authentication management, and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
organisation
CVE-2026-76504
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.9
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Cisco Catalyst SD-WAN Release
First Fixed Release
Earlier than 20.9
Migrate to a fixed release.
infrastructure
20.9.10
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.12
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.12.8
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.15
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.15.6
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.18
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
20.18.4
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
26.1
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
26.1.2
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
26.2
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
infrastructure
26.2.1
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
organisation
Cisco TAC
To help determine whether a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title.
organisation
CVSS
It carries a CVSS score of 9.8 out of 10.
organisation
Cisco Catalyst SD-
Cisco Catalyst SD-WAN Release
First Fixed Release
Earlier than 20.9
Migrate to a fixed release.
Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place.
organisation
Migrate
Cisco Catalyst SD-WAN Release
First Fixed Release
Earlier than 20.9
Migrate to a fixed release.
infrastructure
20.10
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
infrastructure
20.11
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
infrastructure
20.13
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
infrastructure
20.14
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
infrastructure
20.16
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
infrastructure
20.15.605
Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action.
organisation
Cisco SD-WAN Cloud
Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action.
organisation
IP
It also advised security teams investigating potentially compromised SD-WAN systems to check the
serviceproxy-access.log
file located under
/var/log/nms/containers/service-proxy
and the
vmanage-server.log
file under
/var/log/nms/
for entries related to j_security_check from unknown or unauthorized IP addresses.
In Cisco's example, one character of that path is URI-encoded, giving /%6a_security_check, where %6a stands for the letter j.
Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses:
organisation
SD-WAN
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager.
Cisco warns of new SD-WAN zero-day exploited in attacks.
organisation
Technical Assistance Center
The flaw was found while Cisco's Technical Assistance Center (TAC) was handling a support case.
organisation
TAC
The flaw was found while Cisco's Technical Assistance Center (TAC) was handling a support case.
organisation
SD-WAN vManage
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
organisation
Catalyst SD-WAN
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
infrastructure
6,000 WAN devices
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
organisation
Cisco Catalyst SD-WAN
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," it added, advising admins first to
collect admin-tech files
to support the review.
organisation
the Cisco TAC
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," it added, advising admins first to
collect admin-tech files
to support the review.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Saturday, October 3
Threat actors exploited CVE-2026-76504, a vulnerability in T1588.006 protocol, to target U.S. federal agencies.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-76504
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
tactic
T1588.006 - Vulnerabilities
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
attribution
Known Exploited
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
attribution
KEV
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also
added
CVE-2026-76504 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
Tactical Metrics
Metrics
infrastructure
20.9
Software Version
Click for context!
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Cisco Catalyst SD-WAN Release
First Fixed Release
Earlier than 20.9
Migrate to a fixed release.
Metrics
infrastructure
20.9.10
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.12
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.12.8
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.15
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.15.6
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.18
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.18.4
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
26.1
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
26.1.2
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
26.2
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
26.2.1
Software Version
Release train
First fixed release
Earlier than 20.9
Migrate to a fixed release
20.9
20.9.10.1
20.12
20.12.8.2
20.15
20.15.6.1
20.18
20.18.4.1
26.1
26.1.2.1
26.2
26.2.1
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier:
CVE-2026-20182
in May, and
CVE-2026-20245
and
CVE-2026-20262
in June.
Metrics
infrastructure
20.10
Software Version
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
Metrics
infrastructure
20.11
Software Version
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
Metrics
infrastructure
20.13
Software Version
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
Metrics
infrastructure
20.14
Software Version
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
Metrics
infrastructure
20.16
Software Version
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list.
Metrics
infrastructure
20.15.605
Software Version
Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action.
Metrics
infrastructure
6,000
Wan Devices
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
Intelligence Sources
BleepingComputer
2026-09-30
Cisco warns of new SD-WAN zero-day exploited in attacks
BleepingComputer
The Hacker News
2026-09-30
Mastodon BleepingComputer
2026-09-30
Cisco released security updates to address a critical zero-d...
Mastodon BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T14:50
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
API
entity
18x
infrastructure
Software Version
20.9
version
7x
timeline
Temporal Reference
September 30
date
5x
vulnerability
Exploited CVE
CVE-2026-76504
cve
5x
attribution
Attributing Entity
Cisco SD-WAN Cloud-Pro
authority
2x
general metric
20.15.6.1
20
20.15.6.1
Contextual Telemetry
Context Block
15 METRICS
industry
Targeted Sector
Government
sector
vulnerability
CVSS Score
10
score
general metric
Migrate
21
migrate
general metric
20.12.8.2
20
20.12.8.2
general metric
20.18.4.1
26
20.18.4.1
general metric
Table
20
table
general metric
Release Trains
20
release trains
general metric
Case
3
case
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Ports
443
ports
tactic
Cyber Operation Type
Ransomware
tactic
general metric
Cisco Vulnerabilities
90
cisco vulnerabilities
general metric
Cve-2026
76,504
cve-2026
general metric
26.2.1
26
26.2.1
infrastructure
Wan Devices
6,000
wan devices
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.