VORANT. Threat Intelligence Research Sign in Create a free account

Cisco Catalyst SD-WAN flaw exploited in wild

severe vulnerability technologytelecommunications

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR warns an actively exploited Cisco Catalyst SD-WAN vulnerability allows attackers to bypass security policy enforcement.

CERT-FR has issued an advisory regarding CVE-2026-76504, a vulnerability in Cisco Catalyst SD-WAN Software that allows an attacker to bypass the security policy. Cisco has confirmed that this vulnerability is being actively exploited in the wild, making it a priority for affected organizations to patch immediately.

Multiple versions of Catalyst SD-WAN Software are affected, including releases prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. The vulnerability relates to web authentication handling (referenced as 'sdwan-webauth' in Cisco's advisory naming), though specific technical details of the exploitation mechanism are not disclosed in this bulletin. Organizations running Catalyst SD-WAN should consult Cisco's security advisory (cisco-sa-sdwan-webauth-xr8beuuU) for patch guidance and apply fixes immediately given confirmed active exploitation.

Defenders operating Cisco SD-WAN infrastructure should treat this as an urgent patching priority, verify current software versions against the affected ranges listed, and monitor for anomalous authentication or policy bypass activity on SD-WAN management interfaces until patches are applied.

Mentioned in this report

Vulnerabilities CVE-2026-76504KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1246

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,554 reports from 152 sources, 494 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs