Critical Cisco & SonicWall Zero-Days Actively Exploited

Cisco and SonicWall Flaws Under Active Exploit; CISA Issues KEVs

CRITICAL
October 11, 2026
5m read
VulnerabilityPatch ManagementCyberattack

Related Entities

Organizations

Products & Tech

Cisco Catalyst SD-WAN ManagerSonicWall SMA 1000 seriesCouchDB

CVE Identifiers

CVE-2026-76504
CRITICAL
CVSS:9.8
CVE-2026-102255
CRITICAL
CVSS:10

Full Report

Executive Summary

Enterprise networking vendors Cisco and SonicWall have issued emergency patches for critical vulnerabilities in their products that are being actively exploited in the wild. On September 30, Cisco addressed CVE-2026-76504, a 9.8 CVSS authentication bypass flaw in its Catalyst SD-WAN Manager that allows for administrator-level access. Shortly after, on October 7, SonicWall patched CVE-2026-102255, a 10.0 CVSS server-side request forgery (SSRF) vulnerability in its SMA 1000 series remote access gateways. Due to confirmed in-the-wild exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch immediately.


Vulnerability Details

Cisco Catalyst SD-WAN Manager - CVE-2026-76504

  • Vulnerability: Authentication Bypass
  • CVSS Score: 9.8 (Critical)
  • Description: The flaw is due to the improper handling of URI encoding in HTTP requests sent to the product's API. An unauthenticated, remote attacker can send a specially crafted request to gain administrator-level access. This allows for complete takeover of the SD-WAN management platform, enabling an attacker to reconfigure networks, intercept traffic, and pivot to other parts of the corporate network.
  • Affected Product: Cisco Catalyst SD-WAN Manager

SonicWall SMA 1000 Series - CVE-2026-102255

  • Vulnerability: Pre-Authentication Server-Side Request Forgery (SSRF)
  • CVSS Score: 10.0 (Critical)
  • Description: This vulnerability exists in the WorkPlace portal of the SMA 1000 appliance. An unauthenticated, remote attacker can trick the appliance into making requests to arbitrary internal or external services. Attackers have been observed using this flaw to make requests to the device's internal CouchDB service, allowing them to perform unauthorized actions and potentially achieve remote code execution.
  • Affected Products: SonicWall SMA 1000 series (models 6210, 7210, and 8200v)

Exploitation Status

Both vulnerabilities are under active exploitation. Cisco's Product Security Incident Response Team (PSIRT) confirmed it was aware of attacks targeting CVE-2026-76504 before releasing a patch. For CVE-2026-102255, while SonicWall initially reported no evidence of exploitation, security researchers quickly observed active scanning and exploitation attempts against honeypot systems within 72 hours of the patch announcement. The inclusion of both in the CISA KEV catalog underscores the immediate and credible threat they pose.

Impact Assessment

The impact of these vulnerabilities is severe due to the nature of the affected products. Both SD-WAN managers and remote access gateways are high-value, internet-facing targets that act as gatekeepers to corporate networks.

  • A compromise of the Cisco Catalyst SD-WAN Manager could allow an attacker to control an organization's entire wide area network, leading to widespread outages, data interception, and a launchpad for further attacks.
  • Exploitation of the SonicWall SMA 1000 appliance provides attackers with a foothold inside the network perimeter, bypassing traditional defenses and enabling access to internal resources. The SSRF flaw is particularly dangerous as it can be used to scan internal networks and attack other vulnerable services from the trusted position of the VPN appliance.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable or compromised systems:

Type
url_pattern
Value
Unusually encoded characters (%2e, %2f, etc.) in API requests to Cisco SD-WAN Manager.
Description
Potential attempt to exploit CVE-2026-76504.
Type
url_pattern
Value
Requests to /cgi-bin/workplace on SonicWall SMA devices containing unexpected URL parameters.
Description
Potential attempt to exploit CVE-2026-102255 (SSRF).
Type
network_traffic_pattern
Value
Outbound requests from a SonicWall SMA appliance to internal IP addresses, especially to database ports.
Description
Sign of successful SSRF exploitation.
Type
log_source
Value
Web server logs on Cisco SD-WAN Manager
Description
Look for API requests resulting in a 200 OK status from an untrusted IP address.

Detection Methods

  • Log Analysis: For CVE-2026-76504, defenders should review web server and API logs on the Cisco Catalyst SD-WAN Manager for any requests with unusual URL encoding or successful administrative access from unknown IP addresses. For CVE-2026-102255, monitor web logs on the SonicWall appliance for suspicious requests to the /cgi-bin/workplace endpoint. Also, monitor internal network traffic for any unexpected requests originating from the SonicWall appliance's IP address.
  • Vulnerability Scanning: Use vulnerability scanners with updated plugins to actively identify affected Cisco and SonicWall appliances on your network.
  • D3FEND Technique: Employ D3FEND Network Traffic Analysis to detect anomalous traffic patterns originating from these appliances, which could indicate post-exploitation activity.

Remediation Steps

  1. Patch Immediately: The primary remediation is to apply the security updates provided by Cisco and SonicWall as soon as possible. Given the active exploitation, this should be treated as an emergency change.
  2. Restrict Access: As a temporary mitigation, if patching is not immediately possible, restrict access to the management interfaces of these devices to a limited set of trusted IP addresses. This reduces the attack surface from the public internet.
  3. Hunt for Compromise: Assume compromise. After patching, review logs for any signs of exploitation that may have occurred before the patch was applied. If evidence is found, activate your incident response plan.

Timeline of Events

1
September 30, 2026
Cisco discloses and patches CVE-2026-76504.
2
October 7, 2026
SonicWall releases hotfixes for CVE-2026-102255 and other vulnerabilities.
3
October 11, 2026
This article was published

MITRE ATT&CK Mitigations

Immediately apply the patches provided by Cisco and SonicWall to remediate the vulnerabilities.

Restrict access to the management interfaces of affected devices to a small set of trusted IP addresses.

Audit

M1047enterprise

Review logs for signs of compromise before and after patching.

D3FEND Defensive Countermeasures

Given that both CVE-2026-76504 and CVE-2026-102255 are critical vulnerabilities in internet-facing appliances and are under active exploitation, the most urgent and effective countermeasure is to apply the vendor-supplied patches immediately. Organizations should activate their emergency patching procedures. For the Cisco Catalyst SD-WAN Manager and SonicWall SMA 1000 series, this involves downloading the appropriate firmware or hotfix and deploying it according to the vendor's instructions. Before patching, take a configuration backup. After patching, verify that the system is running the new, non-vulnerable version and that normal operations are restored. Due to the 'in-the-wild' exploitation, delaying this action exposes the network perimeter to immediate and severe risk of compromise.

As a critical compensating control, especially if patching cannot be performed instantly, organizations must restrict network access to the management interfaces of the affected Cisco and SonicWall devices. This can be achieved by applying strict access control lists (ACLs) on an upstream firewall. The ACL should deny all traffic to the management interface by default and only permit connections from a small, well-defined set of IP addresses belonging to security and network administration staff. This action dramatically reduces the attack surface by preventing attackers on the public internet from reaching the vulnerable interfaces. This directly mitigates the threat from unauthenticated remote attackers and provides a crucial layer of defense while the patching process is underway.

To detect successful exploitation of the SonicWall SSRF vulnerability (CVE-2026-102255), security teams must monitor for anomalous traffic originating from the SonicWall appliance's internal interface. Deploy network sensors or analyze NetFlow data to look for the appliance initiating connections to other internal systems. Pay close attention to connections to sensitive servers like domain controllers, file servers, or internal databases. Any such connection that is not part of a documented, expected administrative function is highly suspicious and likely indicates that an attacker has exploited the SSRF flaw to pivot into the internal network. Establishing a baseline of normal traffic from the appliance is key to identifying these malicious deviations.

Timeline of Events

1
September 30, 2026

Cisco discloses and patches CVE-2026-76504.

2
October 7, 2026

SonicWall releases hotfixes for CVE-2026-102255 and other vulnerabilities.

Sources & References

What Happened This Week in the Cisco and SonicWall Zero-Day Cluster
Tech Insider (tech-insider.org) •October 10, 2026
Max severity SonicWall SMA1000 flaw now exploited in attacks
BleepingComputer (bleepingcomputer.com) •October 10, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Zero-DayVulnerabilityCiscoSonicWallCISAKEVSSRFAuthentication Bypass

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.