VDB
CVE-2026-76504
CVE-2026-76504
PUBLISHED
KEV
As of September 30, 2026, Cisco is affected by a vulnerability in the following product: Cisco Catalyst SD-WAN Manager Versions prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1 On September 30, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
EPSS 1.58% · 74.6th percentile
Risk Scores
EPSS Score
1.58%
74.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versions | Versions prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1 |
Timeline
- Sep 30, 2026 CISA KEV Added
- Sep 30, 2026 VulnCheck KEV Exploitation
- Sep 30, 2026 Coalition ESS Score
- Sep 30, 2026 CVE Published
- Oct 1, 2026 VulnCheck KEV Exploitation
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 2, 2026 CVE Updated
References
- https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-978 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU vendor
- https://sec.cloudapps.cisco.com/security/center/publicationListing.x vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504 advisory