Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical Cisco Catalyst SD-WAN Manager Vulnerability - CVE-2026-76504

Cisco has identified a critical zero‑day vulnerability (CVE-2026-76504) in Cisco Catalyst SD‑WAN Manager, currently under active exploitation, which may allow an unauthenticated remote attacker to gain administrator‑level access to affected systems.
 
Affected Systems:
 
Cisco Catalyst SD-WAN Manager: all release versions earlier than 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.
 
Security Risks
 
Successful exploitation could allow an unauthenticated attacker to gain administrator-level access to the SD-WAN Manager, potentially allowing unauthorized changes to network configurations and other administrative actions.
 
For the full list of security patches released by Cisco, please refer to Cisco Security Advisories.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Apply the latest supported security updates for Cisco Catalyst SD‑WAN Manager as soon as possible to address the vulnerability.
 
Upgrade to the following supported versions:
 
2. Cisco Catalyst SD-WAN Manager: upgrade to version 20.9.10.1 or above, 20.12.8.2 or above, 20.15.6.1 or above, 20.18.4.1 or above, 26.1.2.1 or above, and 26.2.1 or above.
 
3. Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

02 October 2026

© 2026 National Cyber Security Authority