Enterprise networking vendors Cisco and SonicWall have issued emergency patches for critical vulnerabilities in their products that are being actively exploited in the wild. On September 30, Cisco addressed CVE-2026-76504, a 9.8 CVSS authentication bypass flaw in its Catalyst SD-WAN Manager that allows for administrator-level access. Shortly after, on October 7, SonicWall patched CVE-2026-102255, a 10.0 CVSS server-side request forgery (SSRF) vulnerability in its SMA 1000 series remote access gateways. Due to confirmed in-the-wild exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch immediately.
Both vulnerabilities are under active exploitation. Cisco's Product Security Incident Response Team (PSIRT) confirmed it was aware of attacks targeting CVE-2026-76504 before releasing a patch. For CVE-2026-102255, while SonicWall initially reported no evidence of exploitation, security researchers quickly observed active scanning and exploitation attempts against honeypot systems within 72 hours of the patch announcement. The inclusion of both in the CISA KEV catalog underscores the immediate and credible threat they pose.
The impact of these vulnerabilities is severe due to the nature of the affected products. Both SD-WAN managers and remote access gateways are high-value, internet-facing targets that act as gatekeepers to corporate networks.
The following patterns may help identify vulnerable or compromised systems:
url_pattern%2e, %2f, etc.) in API requests to Cisco SD-WAN Manager.url_pattern/cgi-bin/workplace on SonicWall SMA devices containing unexpected URL parameters.network_traffic_patternlog_source/cgi-bin/workplace endpoint. Also, monitor internal network traffic for any unexpected requests originating from the SonicWall appliance's IP address.Immediately apply the patches provided by Cisco and SonicWall to remediate the vulnerabilities.
Restrict access to the management interfaces of affected devices to a small set of trusted IP addresses.
Given that both CVE-2026-76504 and CVE-2026-102255 are critical vulnerabilities in internet-facing appliances and are under active exploitation, the most urgent and effective countermeasure is to apply the vendor-supplied patches immediately. Organizations should activate their emergency patching procedures. For the Cisco Catalyst SD-WAN Manager and SonicWall SMA 1000 series, this involves downloading the appropriate firmware or hotfix and deploying it according to the vendor's instructions. Before patching, take a configuration backup. After patching, verify that the system is running the new, non-vulnerable version and that normal operations are restored. Due to the 'in-the-wild' exploitation, delaying this action exposes the network perimeter to immediate and severe risk of compromise.
As a critical compensating control, especially if patching cannot be performed instantly, organizations must restrict network access to the management interfaces of the affected Cisco and SonicWall devices. This can be achieved by applying strict access control lists (ACLs) on an upstream firewall. The ACL should deny all traffic to the management interface by default and only permit connections from a small, well-defined set of IP addresses belonging to security and network administration staff. This action dramatically reduces the attack surface by preventing attackers on the public internet from reaching the vulnerable interfaces. This directly mitigates the threat from unauthenticated remote attackers and provides a crucial layer of defense while the patching process is underway.
To detect successful exploitation of the SonicWall SSRF vulnerability (CVE-2026-102255), security teams must monitor for anomalous traffic originating from the SonicWall appliance's internal interface. Deploy network sensors or analyze NetFlow data to look for the appliance initiating connections to other internal systems. Pay close attention to connections to sensitive servers like domain controllers, file servers, or internal databases. Any such connection that is not part of a documented, expected administrative function is highly suspicious and likely indicates that an attacker has exploited the SSRF flaw to pivot into the internal network. Establishing a baseline of normal traffic from the appliance is key to identifying these malicious deviations.
Cisco discloses and patches CVE-2026-76504.
SonicWall releases hotfixes for CVE-2026-102255 and other vulnerabilities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.