CISA KEV: Actively Exploited Cisco SD-WAN and FortiMail Flaws Demand Immediate Patching
CISA KEV adds exploited Cisco SD-WAN Manager auth bypass (CVE-2026-76504) and FortiMail path traversal (CVE-2026-104286). Patch and hunt now.
- CISA added two critical, actively exploited flaws to its KEV catalog: Cisco Catalyst SD-WAN Manager authentication bypass (CVE-2026-76504) and Fortinet FortiMail path traversal (CVE-2026-104286, CVSS 9.8).
- Both are internet-facing edge appliances; exploitation is confirmed in the wild, and Cisco says this is its fifth SD-WAN zero-day of 2026.
- Districts and agencies using these products must patch immediately, restrict management access, and hunt for signs of prior compromise.
What to do now
- Inventory every Cisco Catalyst SD-WAN Manager (vManage) and FortiMail instance, including lab, forgotten, and vendor-managed units; record firmware versions and internet exposure.
- Apply Cisco's and Fortinet's patched releases immediately and verify the version after reboot. If no fix is available, take management and mail interfaces off the public internet and place them behind VPN or IP allowlists.
- Enforce MFA and source-IP allowlists on all admin portals; rotate credentials, API keys, and certificates that touched either appliance.
- Hunt for compromise: for SD-WAN, look for unexpected admin logins, configuration changes, new tunnels or rogue peers; for FortiMail, look for traversal requests, new files, modified configs, unexpected outbound connections, and new admin accounts. Preserve logs.
- If compromise is confirmed, isolate and rebuild rather than clean in place; report to CISA or the Canadian Centre for Cyber Security and your regional coordinator, and check KEV remediation deadlines.
Related items
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
- U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
- New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- CISA Adds One Known Exploited Vulnerability to Catalog