Cisco races to patch an actively exploited SD-WAN flaw

Health systems should inventory internet-facing SD-WAN managers and patch them now.

MedRisk Staff
By
2 Min Read

Cisco has shipped emergency fixes for a critical flaw in the software hospitals and clinics use to manage wide-area networks, warning that attackers are already exploiting it.

The bug, tracked as CVE-2026-76504, lives in Cisco Catalyst SD-WAN Manager’s login handling. A remote attacker with no credentials can abuse URI encoding in an HTTP request to slip past an authentication rule and act as the admin user, a role with full control of the device. Cisco scored the flaw 9.8 out of 10. CISA added it to the Known Exploited Vulnerabilities catalog on September 30.

Cisco says a support case tipped it off to the attacks, which it dates to September 2026. The vendor has not disclosed how many customers were struck, when the campaigns began, or who ran them, and internet-facing managers are the ones exposed.

For health systems, SD-WAN Manager is the control plane for the links that connect hospitals, clinics and imaging centers. Admin-level access there can expose network configuration and routing detail and hand an intruder a path toward clinical and billing systems.

No workaround exists, so IT teams should inventory internet-facing managers, apply the fixed release for their software train, and hunt for signs of the exploit while patching. The flaw affects SD-WAN Manager regardless of how it is configured.

Share This Article