← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO PŘES CVE KEV ✓

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]

Číst originál na BleepingComputer →

4 zprávy z 4 zdrojů · první · zachyceno CZ · EN/orig

Cisco US IT

tg: zneužíváno tg: zranitelnost tp: identita

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-76504 9.8 3.1 · cisco KEV ✓ –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 4

  1. · BleepingComputer US nadpis události

    Cisco warns of new SD-WAN zero-day exploited in attacks

    Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]

  2. · CSIRT Itálie (ACN) IT

    Cisco: rilevato sfruttamento in rete di una vulnerabilità in Catalyst SD-WAN Manager

    Cisco ha rilevato lo sfruttamento in rete di una vulnerabilità critica, identificata tramite la CVE-2026-76504, in Cisco Catalyst SD-WAN Manager, soluzione per la gestione di ambienti SD-WAN.

  3. · Cisco PSIRT US

    Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to…

  4. · zachyceno · CISA KEV US

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (CVE-2026-76504)

    CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog. Affected product: Cisco Catalyst SD-WAN Manager. Remediation due date: 2026-10-03.