Cisco has issued security updates for an authentication bypass bug in Catalyst SD-WAN Manager, tracked as CVE-2026-76504, which BleepingComputer reports is being actively exploited in the wild to gain administrator-level access. At time of publication, the affected-version tables, fixed releases, CVSS rating and interim mitigations have not been independently verified against Cisco's advisory — this piece is a heads-up to get ahead of the disclosure, not a substitute for the advisory itself. Operators should work from Cisco's published advisory for every version number and mitigation step, and treat the checklist below as the starting point for that work.

Why This Is a Controller Problem, Not an Edge-Device Problem

The critical angle here is scope. Catalyst SD-WAN Manager is where administrators define policy, routing behaviour and credentials across an entire branch and data-centre estate. An attacker who reaches admin access through this bypass would not need to compromise each edge device in turn — in principle they could alter configuration, influence routing, and harvest stored credentials straight from the controller. That asymmetry is what separates this from a routine router CVE, and it is why the operational question for network teams is blunt: which management-plane software is running, and where does it sit?

Immediate Action Checklist

  1. Inventory the management platform — list every Catalyst SD-WAN Manager installation, along with any related IOS XE management components, and record the running versions. Note that Cisco's product naming between these two components has blurred before; confirm site by site exactly which management-plane software is deployed.
  2. Check against the official advisory — use the affected and fixed version tables in Cisco's own advisory to determine which systems need immediate upgrading.
  3. Limit management-plane exposure — confirm the SD-WAN Manager management interface is only reachable from necessary internal networks, and review existing access controls and authentication settings.
  4. Review accounts and logs — check admin account activity, configuration change records and credential usage for patterns that differ from the norm.

Each of these steps stands on its own regardless of which versions turn out to be affected. What should not happen in the interim is upgrading blind or applying unverified mitigation: the advisory is the only source that can tell you which releases are vulnerable, which are fixed, and what to do if you cannot patch immediately.

Open Questions for the Advisory

Three specifics remain unresolved here and must come straight from Cisco: the affected and fixed version ranges, the CVSS severity rating, and any interim mitigations the company recommends for systems that cannot be upgraded immediately. It is also not yet clear from secondary reporting whether the active-exploitation attribution originates from Cisco's own telemetry or from third-party incident data, and whether attackers need authentication or network proximity to reach the vulnerable code. All of these details should be confirmed against the Cisco advisory before any remediation decision is taken.

Source: BleepingComputer, "Cisco warns of new SD-WAN zero-day exploited in attacks" — link. Operators should also consult Cisco's own security advisory for the authoritative affected versions, fixed releases and mitigations.


Cisco 已就 Catalyst SD-WAN Manager 一項認證繞過漏洞發出安全更新,該漏洞編號為 CVE-2026-76504;據 BleepingComputer 報導,此漏洞正遭網絡上活躍利用,以取得管理員層級存取權限。截至本文刊出時,受影響版本表格、修補版本、CVSS 評分及臨時緩解措施均未與 Cisco 官方通告獨立核對——本文僅為先行提示,讓讀者搶先掌握披露資訊,並不能取代通告本身。營運商在版本號碼及緩解步驟方面,一切均應以 Cisco 公佈的通告為準,並可將以下清單作為着手工作的起點。

為何這是控制器(Controller)的問題,而非邊緣裝置(Edge Device)的問題

關鍵在於範圍。Catalyst SD-WAN Manager 是管理員制定策略、路由行為及憑證的所在,覆蓋整個分支機構及資料中心系統。若攻擊者透過此繞過漏洞取得管理員存取權限,便毋須逐一攻陷每個邊緣裝置——原則上,他們可直接從控制器修改設定、影響路由,並擷取已儲存的憑證。這種不對稱性,正是一般路由器 CVE 之間的分別,亦是網絡團隊需要正面處理的營運問題:管理面(management plane)軟件正在運行哪個版本,以及它部署在哪裡?

即時行動清單 (Immediate Action Checklist)

  1. 盤點管理平台 — 列出所有 Catalyst SD-WAN Manager 及相關 IOS XE 管理組件的安裝位置與運行版本。注意 Cisco 的產品命名在這兩個組件之間曾經模糊,務必逐站確認實際部署的是哪套管理面軟件。
  2. 對照官方安全通告 — 以 Cisco 原始通告中的受影響版本與修補版本為準,確認哪些系統需要立即升級。
  3. 限制管理面暴露 — 確認 SD-WAN Manager 管理介面只對必要的內部網絡開放,並覆核現有的存取控制及認證設定。
  4. 檢視帳戶與日誌 — 檢查管理員帳戶活動、設定變更記錄及憑證使用情況,留意與平時不同的活動模式。

無論最終確認哪些版本受影響,上述每一步均可獨立執行。然而,期間絕不應盲目升級,或套用未經證實的緩解措施:通告是唯一能告訴你哪些版本存在漏洞、哪些已修補、以及未能即時套用補丁時應如何應對的來源。

尚待通告確認的事項

以下三點目前仍未明確,必須直接查閱 Cisco 原始通告:受影響及已修補的版本範圍、CVSS 嚴重程度評分,以及公司建議的臨時緩解措施(適用於無法立即升級的系統)。此外,次級報道尚未清楚指出,活躍利用的歸因來自 Cisco 自身的遙測資料,還是第三方事件資料;攻擊者是否需要認證或網絡近距離接觸(network proximity)才能觸及有漏洞的代碼,亦未明確。在作出任何補救決定前,上述所有細節均應先與 Cisco 通告核對。

資料來源:BleepingComputer,"Cisco warns of new SD-WAN zero-day exploited in attacks" — 連結。營運商亦應查閱 Cisco 自身的安全通告,以獲取具權威性的受影響版本、修補版本及緩解措施。

新聞來源 / Original News Source