Exploited Auth Bypass in Cisco Catalyst SD-WAN Manager Lands on CISA's KEV List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an authentication bypass in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog after evidence emerged that the flaw is being exploited in the wild — a listing reported this week by The Hacker News. For the many organizations that treat Cisco advisories as routine patch-cycle items, the KEV entry converts the problem into one that carries an explicit remediation date.

The flaw is tracked as CVE-2026-76504 and carries a CVSS base score of 9.8, placing it in the critical range on the CVSS scale. It is an authentication bypass: an unauthenticated remote attacker can reach an affected system without valid credentials. Those three attributes — no authentication required, remote reachability, critical impact — are the profile that typically earns a KEV listing in the first place.

Two key records matter for anyone acting on this, and both should be read first-hand. CISA's catalog entry for CVE-2026-76504 carries the remediation due date that applies to an organization's obligations. Cisco's product security advisory for the same identifier carries the affected and fixed software releases. Neither the date nor the version list should be taken from secondary reporting, and any deadline inferred from an announcement date rather than read from the KEV record is a guess — a distinction that matters when the number of days left is the whole point of the exercise.

Why SD-WAN controllers attract fast-moving attacks

Catalyst SD-WAN Manager is the control plane of Cisco's SD-WAN fabric — the component that sets policy, shapes application routing and pushes configuration out to distributed edge devices. It is not the data path itself, but it dictates what the data path is allowed to do. A breach of that plane hands an attacker both visibility into and influence over WAN-wide policy, an impact footprint far broader than compromising any single branch router.

That is why controller-level authentication bypasses tend to get exploited quickly. A foothold on a management plane fans out across the entire network in one step, and the interface is frequently internet-exposed, because administrators need remote reach into distributed sites.

Two conclusions follow for teams running Cisco's SD-WAN stack. First, the listing confirms the bug is not hypothetical: the KEV catalog exists to capture vulnerabilities where exploitation has actually been observed. Second, a KEV entry carries a federal remediation deadline — a date by which U.S. federal civilian executive branch agencies must act — that many large enterprises and their auditors adopt as a de facto benchmark for internal patching windows, regardless of whether the same obligation technically binds them.

It is worth being precise about what the listing does not say. A KEV entry establishes that CISA has evidence of exploitation; it does not identify the attackers, the scale of the damage, or whether any particular organization has been hit. Coverage that treats "on KEV" as a claim of compromise overstates the record, and defensive decisions made on that basis can be the wrong ones.

What to do this week

  1. Establish exposure. Determine whether any Cisco Catalyst SD-WAN Manager instances run in your estate, and how they are reachable — in particular whether the management interface is exposed beyond a hardened administrative network.
  2. Consult Cisco's advisory for version mapping. Cisco's product security advisory for CVE-2026-76504 is the authoritative list of affected and fixed releases. Compare your deployment against it directly, rather than against a version table reproduced elsewhere.
  3. Read the KEV record. Consult CISA's catalog entry for CVE-2026-76504 to confirm the remediation due date that applies to your obligations, and to capture any additional guidance CISA has attached to the entry.
  4. Patch first, then contain. Upgrade to a fixed release once your deployment has been matched against Cisco's advisory. Where an immediate upgrade is not feasible, restrict management-plane access to a tightly controlled administrative network and require multi-factor authentication for administrative sessions.

That last point deserves a label. Multi-factor enforcement and administrative-network segmentation are general defensive practice, not vendor-supplied mitigations for this specific flaw. Until Cisco's advisory is consulted, treat them as interim containment under your own security controls — and replace them with whatever Cisco recommends as soon as the advisory is in hand.

A global urgency signal, not a U.S.-only compliance item

Hong Kong organizations running Cisco SD-WAN infrastructure should read this listing as a worldwide warning rather than a foreign regulatory event. Active-exploitation confirmation plus a hard federal deadline, anywhere in the world, is a reasonable trigger for near-term patch scheduling, and it is worth working through established channels — HKCERT advisories, vendor bulletins, internal vulnerability-management reviews — when prioritizing the work.

The broader point for the region's network teams is the one the KEV program exists to enforce. A critical, remotely exploitable authentication bypass on a network management plane is not a backlog item. It is a patch this week, or a containment decision taken deliberately, with a clear-eyed view of what is being traded away in the meantime.


Cisco Catalyst SD-WAN Manager 已被利用的認證繞過漏洞登上 CISA KEV 名單

在有證據顯示該漏洞已被實際利用之後,美國網絡安全及基礎設施安全局(CISA)已將 Cisco Catalyst SD-WAN Manager 的一項認證繞過漏洞列入其「已知被利用漏洞」(Known Exploited Vulnerabilities,KEV)目錄;此項列名經 The Hacker News 本週報道。對於許多視 Cisco 公告為一般修補周期事項的機構而言,此項 KEV 列名將問題轉化為一項帶有明確修補到期日的項目。

該漏洞編號為 CVE-2026-76504,CVSS 基準評分為 9.8 分,屬 CVSS 評分體系中的極嚴重級別。這是一項認證繞過漏洞:未經認證的遠端攻擊者可在沒有有效憑證的情況下連接至受影響系統。無需認證、可從遠端觸及、影響嚴重 —— 這三項特徵,正是令一項漏洞通常會被列入 KEV 目錄的原因。

任何就此採取行動的人士,都應留意兩項關鍵紀錄,且兩者均應直接查閱原文。CISA 目錄中 CVE-2026-76504 的條目,載有適用於機構相關義務的修補到期日;Cisco 就同一漏洞編號發出的產品安全公告,則載有受影響及已修復的軟件版本。無論日期或版本清單,均不應取自二手報道;任何從公告日期推測而非從 KEV 記錄直接查閱而得的限期,都只不過是猜測 —— 當剩餘天數正是整個行動的關鍵時,這個區別至關重要。

為何 SD-WAN 控制器特別容易成為迅速攻擊的目標

Catalyst SD-WAN Manager 是 Cisco SD-WAN 架構的控制平面(control plane)—— 負責設定政策、規劃應用程式路由,以及將配置推送至分散式邊緣裝置的元件。它本身並非數據傳輸路徑(data path),但卻決定了數據傳輸路徑被允許作出什麼行為。控制平面一旦被攻陷,攻擊者便可同時獲得對整個廣域網絡(WAN)政策的可見度與影響力,其衝擊範圍遠超入侵任何單一遠端站點的路由器。

這正是為何控制層級的認證繞過漏洞往往會被迅速利用。在管理平面(management plane)取得立足點,只需一步便能擴展至整個網絡,而該界面通常直接暴露於互聯網,因為管理員需要遠端連接至分散各處的站點。

對採用 Cisco SD-WAN 技術的團隊而言,可得出兩點結論。第一,此次列名證實該漏洞並非假設性的問題:KEV 目錄的存在意義,正是要收錄實際已觀察到被利用的漏洞。第二,KEV 記錄帶有聯邦修補限期 —— 即美國聯邦民事行政機構必須採取行動的最後限期 —— 許多大型企業及其核數師將此視為內部修補周期的既成參考基準,無論相同的法律義務在技術上是否約束他們。

有必要準確指出該列名沒有表示的事項。KEV 記錄確立了 CISA 擁有被利用的證據,但並沒有指明攻擊者身份、損失規模,或任何特定機構是否已被入侵。將「列入 KEV」當作已被入侵的宣稱來解讀,會過度引申有關記錄的內容,據此作出的防禦決策亦可能有誤。

本週應採取的行動

  1. 確認風險暴露範圍。 確定您的網絡環境中是否有任何 Cisco Catalyst SD-WAN Manager 實例在運行,以及它們如何被觸及 —— 特別是管理界面是否已超出加固的管理網絡範圍而對外暴露。
  2. 查閱 Cisco 公告以取得版本對照。 關於 CVE-2026-76504 受影響及已修復的版本,Cisco 本身發出的產品安全公告是權威清單。請直接以您的部署環境與公告內容作核對,而非參考其他地方轉載的版本表。
  3. 查閱 KEV 記錄。 查閱 CISA 目錄中 CVE-2026-76504 的條目,核實適用於您各項義務的修補到期日,並記錄 CISA 附加在該條目上的任何額外指引。
  4. 先完成修補,後作遏制。 當您已將部署環境與 Cisco 公告核對妥當後,便升級至已修復的版本。如無法即時升級,則須將管理平面的存取限制於受嚴密管控的管理網絡,並要求管理工作階段必須使用多因素認證(multi-factor authentication)。

最後一點值得額外說明。強制多因素認證及管理網絡分段屬一般性的防禦措施,並非供應商針對此特定漏洞提供的緩解方案。在查閱 Cisco 公告之前,應將此等措施視為在自身安全管控下的臨時遏制手段,並在取得公告後,盡快改用 Cisco 所建議的方案取而代之。

這是一項全球性的緊急警訊,而非僅關乎美國的合規事項

在香港營運 Cisco SD-WAN 基礎設施的機構,應將此項列名理解為全球性的警訊,而非一項境外監管事件。確認已被積極利用,加上全球任何地方設有硬性的聯邦限期,已足夠成為近期安排修補工作的合理觸發條件。在確定工作優先次序時,值得透過既有渠道 —— 如香港電腦保安事故協調中心(HKCERT)的公告、供應商通報、內部漏洞管理審視 —— 進行跟進。

對本區網絡團隊而言,要點與 KEV 計劃的宗旨一致:網絡管理平面上一項嚴重、可從遠端利用的認證繞過漏洞,絕非可留待日後處理的項目。要麼在本週內完成修補,要麼是經過深思熟慮、權衡取捨後作出的遏制決定 —— 清楚知道在這段期間為此所放棄的究竟是什麼。

新聞來源 / Original News Source