Cisco Catalyst SD-WAN Manager security update for CVE-2026-76504
Security Patch Release
Summary
Hide ▲
Show ▼
Cisco released security updates for Catalyst SD-WAN Manager to fix CVE-2026-76504, a critical zero-day that attackers are actively exploiting. The update covers deployments of the network management platform used to administer SD-WAN devices, and Cisco said customers should move to a fixed software release. The flaw can let unauthenticated attackers reach admin privileges remotely.
Related Happenings
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
Campaign
H score38
First: 25.06.2026 17:15
Last: 25.06.2026 17:15
Sources 1
About this happening:
An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign
CampaignAbout this happening: An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...
Cisco security patch release for CVE-2026-20245
Security Patch Release
H score38
First: 25.06.2026 00:29
Last: 25.06.2026 00:29
Sources 1
About this happening:
Cisco released security updates for Cisco Catalyst SD-WAN after CVE-2026-20245 was linked to root-level command execution, and customers were told to move to fixed sof...
Cisco security patch release for CVE-2026-20245
Security Patch ReleaseAbout this happening: Cisco released security updates for Cisco Catalyst SD-WAN after CVE-2026-20245 was linked to root-level command execution, and customers were told to move to fixed sof...
CISA adds CVE-2026-20262 to KEV and orders federal fixes
Public Sector Action
H score32
First: 16.06.2026 09:05
Last: 16.06.2026 09:05
Sources 1
About this happening:
CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...
CISA adds CVE-2026-20262 to KEV and orders federal fixes
Public Sector ActionAbout this happening: CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...
Cisco security patch release for CVE-2026-20262
Security Patch Release
H score47
First: 15.06.2026 20:12
Last: 15.06.2026 20:12
Sources 1
About this happening:
Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root pr...
Cisco security patch release for CVE-2026-20262
Security Patch ReleaseAbout this happening: Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root pr...
Cisco Unified Communications Manager security update for CVE-2026-20230
Security Patch Release
H score56
First: 04.06.2026 14:09
Last: 04.06.2026 14:09
Sources 1
About this happening:
Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...
Cisco Unified Communications Manager security update for CVE-2026-20230
Security Patch ReleaseAbout this happening: Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...
Timeline
-
30.09.2026 17:46 3 articles · 2h ago
Cisco releases security updates for critical Catalyst SD-WAN Manager zero-day
Mitigation Patch UpdateCisco released security updates for Catalyst SD-WAN Manager to address CVE-2026-76504, a critical zero-day that allows unauthenticated remote attackers to bypass an API authentication rule and reach admin privileges. Cisco said it became aware of active exploitation in September 2026, urged customers to upgrade to a fixed software release, and advised administrators to look for %6a in malicious requests and j_security_check entries in serviceproxy-access.log and vmanage-server.log.
Show sources
- Cisco warns of new SD-WAN zero-day exploited in attacks — www.bleepingcomputer.com — 30.09.2026 17:46
- Cisco warns of new SD-WAN zero-day exploited in attacks — www.bleepingcomputer.com — 30.09.2026 17:46
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager — thehackernews.com — 30.09.2026 18:24