poslední zpráva
SPOJENO PŘES CVE KEV ✓
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
Cisco US IT
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-76504 | 9.8 3.1 · cisco | KEV ✓ | – |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Jak se o tom psalo 4
-
· BleepingComputer US nadpis události
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
-
· CSIRT Itálie (ACN) IT
Cisco: rilevato sfruttamento in rete di una vulnerabilità in Catalyst SD-WAN Manager
Cisco ha rilevato lo sfruttamento in rete di una vulnerabilità critica, identificata tramite la CVE-2026-76504, in Cisco Catalyst SD-WAN Manager, soluzione per la gestione di ambienti SD-WAN.
-
· Cisco PSIRT US
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to…
-
· zachyceno · CISA KEV US
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (CVE-2026-76504)
CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog. Affected product: Cisco Catalyst SD-WAN Manager. Remediation due date: 2026-10-03.