A critical authentication bypass in Cisco SD-WAN Manager, tracked as CVE-2026-76504, is being actively exploited. CISA added it to its Known Exploited Vulnerabilities catalogue on 1 October. By sending specially crafted HTTP requests, a remote attacker can gain administrator access to the management system without a password.
You may never have heard of SD-WAN, so here is why a UK small business should still care.
Who is affected
SD-WAN Manager is the control console for Cisco’s software-defined wide area network. It is typically used by organisations with several sites, such as multi-branch retailers, clinics, solicitors, franchises and logistics firms. It decides how traffic flows between offices, the cloud and the internet.
Most small businesses do not run this themselves. But many are connected through a managed service provider, a telecoms reseller or a larger parent group that does. If a provider’s management console is taken over, an attacker can reroute traffic, change security policy or reach every site on the network at once.
That is the real exposure for an SME: not your own kit, but the supplier that manages your connectivity.
What to do today
Ask your provider directly. Email your IT or network supplier with a simple question: “Do you use Cisco SD-WAN Manager, and has CVE-2026-76504 been patched?” You are entitled to a clear answer, and you should keep it on file.
If you run it yourself, patch immediately. Apply Cisco’s fixed release as soon as it is available for your version. If a patch cannot go on today, restrict access to the management interface so it is not reachable from the open internet. Management consoles should sit behind a VPN or an allow-list of trusted addresses.
Look for signs of compromise. Because this is a zero-day that was exploited before a fix, patching alone may not be enough. Review the system for new administrator accounts, unexpected configuration changes and logins from unfamiliar addresses. If anything looks wrong, treat it as an incident and bring in specialist help.
Check your own list of internet-facing systems. If you do not have one, make one this week. You cannot patch what you do not know exists.
Why speed matters
Once a flaw lands on CISA’s exploited list, scanning for vulnerable systems typically ramps up within days. Attackers do not need to target you specifically; automated tools simply look for any exposed console. The gap between disclosure and your supplier patching is the window in which most damage is done, so a slow answer today is itself a risk worth recording.
A pattern worth noticing
This is the latest in a run of exploited flaws in network and edge equipment, including the Citrix NetScaler issues we covered earlier this week. Attackers favour these devices because they sit at the boundary of the network, often go unmonitored and are patched less promptly than laptops.
For a small firm with no in-house security team, the practical answer is to know who is responsible for each device and to hold them to a patching timetable. Our sister site CoolCoding helps businesses document and tidy up this kind of technical estate, and a simple asset register is the first step.
The takeaway
You do not need to understand SD-WAN to act on this. Today, send one email to whoever manages your network and ask whether they are affected and whether they have patched. If the answer is vague or slow, that tells you something important about your supplier, and it is worth knowing before an attacker finds out for you.