Skip to content
Rota Nacional

Cyber ·

CISA adds Cisco SD-WAN flaw to KEV catalog

On September 30, 2026, CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.

On September 30, 2026, CISA reported adding CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is described as a hexadecimal encoding issue in Cisco Catalyst SD-WAN Manager, with evidence of active exploitation.

The agency says vulnerabilities of this kind are a frequent attack vector and pose significant risks to the federal sector. Directive BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize, on a risk basis, remediation of KEV-listed vulnerabilities on publicly exposed assets where exploitation could grant full control of the asset. It also sets expectations for checking for possible compromise before applying fixes.

The directive applies only to FCEB agencies. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize fixing flaws listed in KEV. For possible catalog inclusion, the agency requests a CVE ID, evidence of exploitation, and clear mitigation guidance.

Consult CISA’s alert and the corresponding KEV entry to confirm the details and check for updated vendor guidance. The source text is an automatic translation; compare it with the original notice before making decisions. If you use AI to analyze the material, avoid entering internal data or credentials and follow your organization’s policies.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free