A remote caller with no account just became your SD-WAN administrator.
Cisco says attackers are exploiting CVE-2026-76504 in Catalyst SD-WAN Manager, the controller many enterprises use to run overlay networks. A remote attacker with no login can use the Manager API as the admin user. Fixed builds are out. There’s no workaround. Put that host on the internet and your cybersecurity program is arguing with someone who already has the keys.
Microsoft is watching the twin of this failure on internet-facing Zimbra. CVE-2026-73570 is unauthenticated command injection against mail servers. You can spend a decade polishing the login page. The request never hits it. The box runs a command anyway.
The Overlay Controller Trusted Everyone

SD-WAN Manager pushes policy, credentials, and routing to every spoke. Steal that API and you steal the overlay. Cisco’s advisory reads like an incident because it is one. Exploitation is in the wild, and there’s no knob to twist while you wait for a change window.
Treat the Manager like a domain controller that happens to speak HTTP. You wouldn’t publish that. Plenty of shops still publish this one because the overlay UI felt harmless and the vendor’s default deploy made 443 easy.
Mail is the other public brain. Zimbra on the internet is a command runner with your directory sitting behind it. Microsoft published attack paths and hunting because those paths are occupied. A webmail box that will execute OS commands for an unauthenticated caller is a beachhead, a mail thief, and a pivot in one listening socket.
Your firewall may still show a tidy allow to 443.
That allow is doing threat-protection theater when the application never challenges the caller. Brute-force lockouts, MFA prompts, and password policies never run. The first request is already privileged. SOC tickets about failed logins on the VPN won’t catch an admin API that never failed because it never asked.
Cybersecurity Models Guard the Wrong Door

Google’s analysis says AI-assisted vulnerability research is changing both the pace and the profile of what gets found. Discovered bugs are more likely to enable remote code execution. Unauthenticated admin on a WAN controller and unauthenticated command injection on mail are that class of bug. A model reading a parser doesn’t care that your change board meets Thursdays.
Once those findings leave the lab, mass scanning follows. You’ve seen this movie with every internet-facing appliance this year. The difference now is how fast a mediocre researcher becomes dangerous against a forgotten Manager or a neglected Zimbra.
Defense in depth that starts at the laptop and ends at the SIEM still misses the two hosts that can rewrite your routing table or your mailbox. A lot of cyber security spend still goes to endpoint noise while the management plane listens on a public address with a vendor TLS cert and a smile.
Threat detection that waits for a failed password stays quiet. Incident response that waits for a malware pop starts after the overlay already belongs to someone else. You need detections for admin API calls with no prior session and for mail processes that spawned a shell. You also need to prove those rules have fired in a test, or they are decoration.
Rank the work by blast radius. A stolen overlay controller rewrites how every site reaches the rest of the company.
The honest ranking is simple. Internet-reachable software that can change identity, routing, or execute commands outranks almost everything on your board this week.
Shrink the Admin Surface Today

Security hardening here is reachability work you can finish this afternoon.
Do this in order. Patching without isolation still leaves you racing scanners. Isolation without hunting still leaves you blind to who already called.
- Same day: inventory every internet-facing SD-WAN manager, mail admin, hypervisor console, backup UI, and out-of-band controller. If it can change routing or run OS commands, it is tier-0. External-scan it the way an attacker would, from an address that isn’t on your allowlist.
- Same day: move Catalyst SD-WAN Manager to Cisco’s fixed releases. If you can’t patch in hours, pull public reachability. There’s no workaround. Hunt API access that never authenticated, then rotate overlay credentials, templates, and device certs if the Manager was exposed.
- Same day: patch or isolate internet-facing Zimbra. Unauthenticated command injection is a full host compromise. Rebuild from known-good media. Rotate mailbox credentials, app passwords, and SSO tokens. Capture process trees and mail-service child shells before you wipe, so incident response has a timeline.
- Every week: management and mail admin only through a jump path you own. No direct 443 from the world. Re-prove it with an outside scan after every change. Keep last-fired evidence for unauthenticated-admin and mail-spawn detections so threat detection stays a live control.
A stranger who becomes admin on first call already holds your control plane. Close the socket. Then go prove nobody used it last month.
Sources
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
- Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
