# CISA Adds Cisco SD-WAN Flaw to KEV Catalog

CISA added Cisco Catalyst SD-WAN Manager vulnerability CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30, 2026, after reports of active exploitation. The CVSS 9.8 authentication-bypass flaw has no workaround; upgrading to a fixed release is the stated remediation. The October 3, 2026 remediation deadline for federal civilian executive branch agencies has passed. The signals identify no specific solicitation, contract, or funding, but the vulnerability creates immediate patch-verification and incident-response work for agencies and contractors supporting affected federal networks.

- Federal agencies and their service providers should confirm whether Catalyst SD-WAN Manager deployments are affected, verify upgrades to fixed releases, and check for signs of compromise; the source signals identify no workaround.
- Contractors supporting federal networks should document remediation status and any exceptions, and review incident-response procedures in light of the reported exploitation and elapsed agency deadline.
- Cybersecurity service providers may find demand for vulnerability assessment, patching, and SD-WAN security support, although no funded procurement or solicitation is identified in these signals.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 04, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Federal Civilian Executive Branch agencies (FCEB)

### Vendors
- Cisco (software manufacturer)

### Key Quotes
> Defused posted earlier on X that they've already seen this in the wild.
> — Original poster

### Sources
- [Cisco SD-WAN Zero-Day CVE-2026-76504: CVSS 9.8 Bug](https://tech-insider.org/cisco-sd-wan-zero-day-cve-2026-76504-2026) - tech-insider.org
- [U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog](https://www.reddit.com/r/cybersecurity/comments/1wv7n63/us_cisa_adds_cisco_catalyst_sdwan_manager_flaw_to) - reddit-cybersecurity
- [Cisco SD-WAN Flaw: CVSS 9.8, CISA Deadline Today [2026]](https://shattered.io/cisco-sd-wan-manager-cve-2026-76504-cvss-9-8-2026) - shattered.io