CISA KEV Alert 30 Sept 2026, 17:32 UTC

CISA Warns of Active Exploitation in Cisco SD-WAN Manager Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalogue on 30 September 2026. The vulnerability affects Cisco Catalyst SD-WAN Manager and is known as the Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability. It could allow an unauthenticated remote attacker to access an affected system with the privileges of the admin user.

The flaw results from improper handling of URI encoding in an HTTP request. It is an encoding vulnerability with a network-based attack vector and requires no authentication. The vulnerability carries a CVSS score of 9.8 and a Critical severity rating. The available data does not confirm whether a patch is available; patch status is listed as unknown.

CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available information does not identify use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must complete remediation by 3 October 2026.

CISA requires agencies to apply mitigations in accordance with Cisco’s instructions and comply with its BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Agencies must follow the applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and follow BOD 26-04 patching requirements. Although this requirement directly affects FCEB agencies, all organisations should review their exposure.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline