{"schema":"hottub-news/story/v1","story":"st_ruag2gy4dna6mtrtbsea","title":"CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV","title_en":null,"outlets":2,"brief":null,"page":"https://hottub.news/stories/cisa-catalyst-sd-wan-manager-kev-ruag2gy4dn","count":2,"items":[{"id":"n_a5gourkqyqj3firjcfqa","seq":1118449,"kind":"article","title":"CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV","url":"https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with","published":"2026-10-01T10:33:16Z","seen":"2026-10-01T11:05:37Z","lang":"en","source":{"id":"kite-feedburner-com-5fa171","name":"feedburner.com","domain":"feeds.feedburner.com"},"via":"kite-feedburner-com-5fa171","topics":["cybersecurity"],"authors":["author"],"entities":[{"id":"Q5205058","name":"Cybersecurity and Infrastructure Security Agency","type":"org"}],"image":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8jgm3LMY2zr1S1DmXnvVEPDiTKYR5FXHW7q_6duG1lVPhzbW2ZfJwRM9glqAJrQhBX3HAAiksz-tUpRN4pfT9VWHUksa-1SgHZmKcNUd1tJfsyFiwhtezZN_zBM_cEmqjkECI_2gfWhnqZ1ry2hgDou-qQCB21zbl1RzYN9JB0bRjqzhB2m6gBomg-ow9/s1600/cisa-wan.jpg","mentions":2,"story":"st_ruag2gy4dna6mtrtbsea","category":"science-technology","category_p":0.5699999928474426,"sentiment":"neutral","tone":-0.17000000178813934,"political":0.30000001192092896},{"id":"n_ruag2gy4dna6mtrtbsea","seq":1043726,"kind":"article","title":"美國CISA將思科Catalyst SD-WAN Manager重大漏洞列KEV","url":"https://www.ithome.com.tw/news/179329","summary":"新聞 9月30日 思科針對Catalyst SD-WAN Manager用戶提出警告 ，他們發現及修補已遭利用的重大漏洞CVE-2026-76504，用戶需儘速採取行動。 同一天美國網路安全與基礎設施安全局（CISA）表示 ，他們已經掌握該弱點遭積極利用的證據，將其列入已遭利用的漏洞名單（KEV），聯邦機構需在 10月3日前 完成修補。 CVE-2026-76504源自Catalyst SD-WAN Manager對於HTTP請求裡的URI編碼處理不當，一旦攻擊者成功利用，就能以管理員權限的使用者存取API，CVSS嚴重程度評為9.8分。","published":"2026-10-01T02:41:46Z","seen":"2026-10-01T03:16:49Z","lang":"zh","country":"TW","source":{"id":"kite-ithome-com-tw-c23d09","name":"ithome.com.tw","domain":"ithome.com.tw","outlet":{"wikidata":"Q123398745","name":"iThome","type":"magazine","country":"TW","designations":["magazine","news website"]}},"via":"kite-ithome-com-tw-c23d09","authors":["周峻佑"],"story":"st_ruag2gy4dna6mtrtbsea","category":"science-technology","category_p":0.5600000023841858,"sentiment":"negative","tone":-0.6100000143051147,"political":0.47999998927116394}]}