# Cisco Catalyst SD-WAN flaw exploited in wild

Published: 2026-10-01 · Severity: severe · Sectors: technology, telecommunications
Canonical: https://vorant.io/reports/c6e07711-b71b-5f17-9253-24dbb8d36864/cisco-catalyst-sd-wan-flaw-exploited-in-wild

> CERT-FR warns an actively exploited Cisco Catalyst SD-WAN vulnerability allows attackers to bypass security policy enforcement.

CERT-FR has issued an advisory regarding CVE-2026-76504, a vulnerability in Cisco Catalyst SD-WAN Software that allows an attacker to bypass the security policy. Cisco has confirmed that this vulnerability is being actively exploited in the wild, making it a priority for affected organizations to patch immediately.

Multiple versions of Catalyst SD-WAN Software are affected, including releases prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. The vulnerability relates to web authentication handling (referenced as 'sdwan-webauth' in Cisco's advisory naming), though specific technical details of the exploitation mechanism are not disclosed in this bulletin. Organizations running Catalyst SD-WAN should consult Cisco's security advisory (cisco-sa-sdwan-webauth-xr8beuuU) for patch guidance and apply fixes immediately given confirmed active exploitation.

Defenders operating Cisco SD-WAN infrastructure should treat this as an urgent patching priority, verify current software versions against the affected ranges listed, and monitor for anomalous authentication or policy bypass activity on SD-WAN management interfaces until patches are applied.

## Mentioned in this report

- Vulnerabilities: CVE-2026-76504 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1246

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c6e07711-b71b-5f17-9253-24dbb8d36864/cisco-catalyst-sd-wan-flaw-exploited-in-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
