CISA KEV: Actively Exploited Cisco SD-WAN and FortiMail Flaws Demand Immediate Patching

CISA KEV adds exploited Cisco SD-WAN Manager auth bypass (CVE-2026-76504) and FortiMail path traversal (CVE-2026-104286). Patch and hunt now.

  • CISA added two critical, actively exploited flaws to its KEV catalog: Cisco Catalyst SD-WAN Manager authentication bypass (CVE-2026-76504) and Fortinet FortiMail path traversal (CVE-2026-104286, CVSS 9.8).
  • Both are internet-facing edge appliances; exploitation is confirmed in the wild, and Cisco says this is its fifth SD-WAN zero-day of 2026.
  • Districts and agencies using these products must patch immediately, restrict management access, and hunt for signs of prior compromise.

What to do now

  1. Inventory every Cisco Catalyst SD-WAN Manager (vManage) and FortiMail instance, including lab, forgotten, and vendor-managed units; record firmware versions and internet exposure.
  2. Apply Cisco's and Fortinet's patched releases immediately and verify the version after reboot. If no fix is available, take management and mail interfaces off the public internet and place them behind VPN or IP allowlists.
  3. Enforce MFA and source-IP allowlists on all admin portals; rotate credentials, API keys, and certificates that touched either appliance.
  4. Hunt for compromise: for SD-WAN, look for unexpected admin logins, configuration changes, new tunnels or rogue peers; for FortiMail, look for traversal requests, new files, modified configs, unexpected outbound connections, and new admin accounts. Preserve logs.
  5. If compromise is confirmed, isolate and rebuild rather than clean in place; report to CISA or the Canadian Centre for Cyber Security and your regional coordinator, and check KEV remediation deadlines.

Related items