Cisco is urging administrators of affected Catalyst SD-WAN Manager systems to install fixed software after reporting active exploitation of a critical authentication flaw. Its advisory was updated Oct. 2.
The vulnerability, CVE-2026-76504, can allow an unauthenticated attacker to gain administrative access. Cisco says it became aware of exploitation in September.
A newly released Live Protect shield provides temporary, partial protection. Cisco says upgrading to an appropriate fixed release is the remedy; administrators should use the current advisory to match their software version to the required update.