Skip to content
eastbaycyber

Threat Digest: Cisco SD-WAN Added to CISA KEV

Threat digests 11 min read
EC
East Bay Cyber Editorial Team Updated
Week of 1 OCT 2026

This cybersecurity threat digest October 1 2026 edition covers Cisco SD-WAN, CISA KEV activity, critical vulnerabilities, reported breaches, and actions for defenders.

TL;DR - Cisco Catalyst SD-WAN Manager authentication bypass CVE-2026-76504 is in CISA KEV, with a federal remediation deadline of October 3. - Review exposed management systems, patch critical software, and investigate identity, API, endpoint, and cloud logs. - Treat reported Pentagon and MetaMask incidents, plus the RedFlick campaign, as active defensive priorities.

Top Stories#

Cisco SD-WAN authentication bypass enters CISA KEV

CVE-2026-76504 affects Cisco Catalyst SD-WAN Manager’s API session-based authentication management. The CVSS 9.8 vulnerability could allow an unauthenticated remote attacker to bypass authentication and access the API with administrator privileges.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 30, with a listed federal remediation due date of October 3. Cisco’s security advisory contains the vendor’s mitigation and remediation guidance.

Why it matters: An internet-reachable management plane with an authentication bypass can provide a direct path to administrative control. Organizations should not wait for routine patch cycles or rely solely on perimeter controls.

Analyst’s Take: This is the first item to work because the vulnerability combines administrator-level access, remote unauthenticated access, and a CISA KEV deadline of October 3. Confirm remediation on each Cisco instance and review API and administrative telemetry rather than treating a deployment status as proof that the exposure is closed.

Pentagon personnel records reportedly stolen

The Pentagon’s Defense Manpower Data Center is notifying millions of military service members after hackers reportedly breached a human resources management system and stole personnel data. BleepingComputer reports that the incident affected nearly 3 million people.

Why it matters: Large personnel datasets can support identity theft, targeted phishing, espionage, and social-engineering campaigns. Organizations handling sensitive workforce data should review data minimization, privileged access, retention, and monitoring controls.

MetaMask reports an infrastructure security incident

Cryptocurrency wallet provider MetaMask disclosed an ongoing security incident affecting portions of its infrastructure, according to BleepingComputer.

The available report does not establish the full scope or impact. Users and organizations should rely on official MetaMask communications, avoid unsolicited recovery or verification requests, and review wallet, account, and administrator activity for anomalies.

Star Blizzard uses RedFlick to deliver CosmicPulse

Russian state-linked actor Star Blizzard is reportedly using a new malware installation technique called RedFlick to deploy the CosmicPulse backdoor. BleepingComputer’s report describes the reported delivery method and malware activity.

Why it matters: New delivery techniques can evade detections built around known filenames, hashes, or attachment patterns. Detection engineering should focus on execution chains, identity context, persistence, network behavior, and abnormal use of trusted tools. Teams can also map observed behavior to the MITRE ATT&CK framework when organizing detection and hunting coverage.

Windows 11 26H2 enables settings backup by default for some organizations

Microsoft has enabled Windows settings backup and restore by default on Microsoft Entra-joined and Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2, according to BleepingComputer.

Administrators should determine what settings are synchronized, which users can restore them, how the data is governed, and whether the behavior conflicts with organizational policy or regulatory requirements.

Public exposure of McMinnville records highlights data governance risks

A report from KOIN says sensitive McMinnville records were exposed online.

The report reinforces the need for recurring public exposure reviews, secure document publication workflows, and clear ownership for removing information that should not be publicly accessible. For staff working on untrusted networks, an approved VPN service such as Check NordVPN pricing → may provide an additional privacy layer, but it does not replace access controls, secure publication workflows, or monitoring.

AI investment grows while transportation security results remain uncertain

Kevin Mandia’s AI cybersecurity startup reportedly raised another $255 million, according to The Wall Street Journal’s report. Separately, a transportation cybersecurity report says AI has not yet materially improved defensive outcomes in that sector, as summarized by Yahoo.

Security teams should measure AI projects against concrete outcomes: reduced detection time, better coverage, fewer false positives, faster containment, or improved analyst capacity.

Critical Vulnerabilities#

CVE-2026-76504: Cisco Catalyst SD-WAN Manager

  • Severity: CVSS 9.8
  • Status: Listed in CISA KEV
  • Deadline: October 3, 2026, for the listed federal remediation schedule
  • Impact: Unauthenticated remote access to the API with administrator privileges
  • Action: Apply Cisco’s mitigations and remediation guidance immediately.

Review the Cisco advisory and CISA KEV entry. Prioritize systems with internet-facing management interfaces and investigate unexpected administrative API sessions.

CVE-2026-88920: Apache WSS4J

  • Severity: CVSS 9.8
  • Impact: Authentication bypass and forged authenticated SOAP messages
  • Attack path: A crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key
  • Fixed versions: 4.0.2, 3.0.6, and 2.4.4
  • Action: Upgrade affected deployments and review SAML and SOAP authentication logs.

Apache’s disclosure is available through the Apache security mailing-list archive. The vulnerability is especially relevant to organizations operating SOAP services that accept SAML sender-vouches assertions.

CVE-2026-103395: LightLLM

  • Severity: CVSS 9.8
  • Affected scope: LightLLM through version 1.2.0 in visual_only deployments
  • Impact: Unauthenticated remote code execution through an exposed RPyC service with allow_pickle enabled
  • Privileges: Code executes with service-account privileges
  • Action: Restrict the RPyC service, disable unauthenticated access, remove unsafe deserialization where possible, and upgrade or remove affected deployments.

Review the LightLLM project and issue references and the VulnCheck advisory. Rotate credentials for affected service accounts after exposure or suspected exploitation.

CVE-2026-97248: Booking Activities WordPress plugin

  • Severity: CVSS 9.8
  • Affected scope: Versions through 1.18.7.1
  • Impact: Unauthenticated PHP object injection
  • Action: Update the plugin, disable it, or remove it if it is not required.

See the Patchstack advisory. WordPress administrators should also inspect web-server, PHP, authentication, and file-integrity logs for suspicious activity.

CVE-2026-100253: JetBrains TeamCity

  • Severity: CVSS 8.8
  • Impact: Sandbox escape through the versioned settings Kotlin DSL, potentially leading to code execution
  • Fixed versions: 2026.2, 2026.1.4, and 2025.11.8
  • Action: Upgrade TeamCity and review build agents, tokens, credentials, and recent build configuration changes.

The available vendor reference is JetBrains’ list of fixed security issues. Because TeamCity commonly has access to source repositories, signing keys, deployment credentials, and production environments, isolate unpatched instances from untrusted networks.

What Defenders Should Do Today#

1. Remediate Cisco SD-WAN first

  1. Inventory every Cisco Catalyst SD-WAN Manager instance.
  2. Identify internet-facing, partner-facing, and otherwise reachable management interfaces.
  3. Apply Cisco’s published mitigation or fixed software guidance.
  4. Confirm the remediation on each instance rather than relying on deployment status alone.
  5. Review API, authentication, administrative, and network telemetry for activity outside expected maintenance windows.
  6. Complete the applicable CISA KEV workflow by October 3.

2. Patch or isolate the remaining critical exposures

Prioritize systems using this order:

  1. Internet-facing, unauthenticated services.
  2. Administrative interfaces and identity infrastructure.
  3. CI/CD platforms with access to source code or deployment credentials.
  4. AI inference systems exposing RPyC or other management services.
  5. Public-facing WordPress installations with vulnerable plugins.
  6. SOAP services accepting SAML assertions.

If immediate patching is not possible, restrict access at the network layer, disable unnecessary services, remove vulnerable components, and document compensating controls.

3. Hunt for authentication bypass and administrative abuse

Search logs for:

  • Successful administrative API access without a corresponding normal authentication sequence.
  • New or unexpected administrator sessions.
  • Authentication events from unfamiliar source addresses, geographies, or autonomous systems.
  • SAML assertions that fail expected signature, issuer, audience, or subject validation.
  • SOAP requests with unusual assertion structures or unexpected signing behavior.
  • New TeamCity projects, build configurations, tokens, agents, or credential access.
  • WordPress requests associated with plugin endpoints, unexpected file writes, or PHP process execution.
  • RPyC connections to LightLLM hosts from unapproved networks.

Preserve relevant logs before rotating systems or rebuilding hosts. Tie findings to identity, endpoint, network, and cloud telemetry so investigators can establish a complete session timeline.

4. Audit LightLLM and other AI service deployments

For LightLLM environments:

  • Enumerate visual_only deployments and their listening ports.
  • Identify RPyC services exposed beyond the local host or an approved management network.
  • Confirm whether allow_pickle is enabled.
  • Restrict service-account permissions to the minimum required.
  • Rotate service-account credentials if the service was reachable by untrusted clients.
  • Review process creation, outbound connections, and file changes on inference hosts.
  • Rebuild systems if arbitrary code execution is confirmed.

AI infrastructure should be included in the same vulnerability-management and network-segmentation programs as other production services.

5. Review data exposure and third-party incidents

For organizations handling personnel, customer, or public-sector records:

  • Revalidate access controls for HR and records-management systems.
  • Minimize stored personal data and remove unnecessary historical records.
  • Review third-party service access and notification obligations.
  • Monitor for exposed files, indexes, object-storage paths, and public document links.
  • Prepare targeted user communications for phishing that references a reported incident.
  • Preserve evidence and coordinate legal, privacy, and incident-response teams before making conclusions about scope.

Do not assume that a reported breach or exposure has the same impact across all organizations. Validate whether your systems, users, or data were involved.

6. Investigate RedFlick and CosmicPulse activity

Hunt across email, endpoint, DNS, proxy, and identity telemetry for:

  • Suspicious attachment or link execution chains.
  • Office or document applications spawning scripting engines or command shells.
  • New persistence mechanisms created shortly after a user interaction.
  • Unusual outbound connections from workstations or servers.
  • Credential access followed by lateral movement.
  • Endpoint detections involving CosmicPulse or related malware artifacts.
  • Traffic patterns that do not match the user’s role, device, or normal business activity.

Because delivery details may evolve, avoid relying only on static indicators. Use behavioral detections and correlate activity across the initial-access, execution, persistence, and command-and-control stages.

7. Assess Windows 11 26H2 settings backup

Before broad deployment or after an upgrade, document:

  • Which Windows settings are backed up.
  • Which identities can trigger restoration.
  • Whether restored settings can alter security controls or user workflows.
  • Where synchronized data is stored and how it is protected.
  • How backup and restore events appear in administrative and cloud audit logs.
  • Whether the feature conflicts with data-residency, retention, or configuration-management requirements.

Use a pilot group to validate expected behavior, then update endpoint baselines and user guidance.

Technical Notes#

Verify exposed management services

Use approved asset-inventory and network-scanning processes. Do not scan systems without authorization.

# Review local listening services on a Linux host
ss -lntup

# Review established TCP connections
ss -tnp state established

# Search an exported inventory for likely management services
grep -Ei 'sdwan|teamcity|lightllm|rpyc|wordpress|wss4j' asset-inventory.csv

For Cisco SD-WAN Manager, use the platform’s supported administrative tools and Cisco guidance rather than relying on generic service detection to determine whether a system is vulnerable.

Example log triage workflow

Normalize events into a common timeline containing:

timestamp
source_address
destination
username
authentication_result
application
session_id
user_agent
administrator_action
process_name
parent_process

Then prioritize combinations such as:

authentication_result=success
AND username in privileged_accounts
AND source_address not in approved_admin_ranges
administrator_action in (create_token, change_config, add_user, deploy_build)
AND timestamp outside approved_change_window

These are investigation filters, not proof of exploitation. Validate each result against change tickets, administrator activity, asset ownership, and endpoint telemetry.

Example network-control pattern for an internal service

Where supported by the product and change process, limit administrative services to approved management networks:

ALLOW  management_subnet  ->  application_admin_port
DENY   any                ->  application_admin_port
LOG    denied_connections

Apply controls at firewalls, security groups, host firewalls, and service configuration layers as appropriate. A network restriction should complement, not replace, vendor patching.

WordPress containment checks

For a potentially exposed WordPress installation:

# Review recent web requests
awk '$4 >= "[01/Oct/2026:00:00:00"' /var/log/nginx/access.log | tail -n 200

# Find recently modified PHP files in the web root
find /var/www -type f -name '*.php' -mtime -7 -printf '%TY-%Tm-%Td %TT %p\n'

# Review enabled plugins with the site's supported administration tooling
wp plugin list --status=active

Preserve logs and obtain a forensic copy before deleting files or reinstalling the plugin. Commands and paths vary by deployment.

Executive Brief#

The first move is to inventory and remediate every Cisco Catalyst SD-WAN Manager instance, starting with internet-facing management interfaces, because CVE-2026-76504 combines a critical authentication bypass with CISA KEV listing and a near-term remediation deadline. Confirm the change on each instance and review administrative API activity before moving to the remaining critical exposures.

Next, patch or isolate Apache WSS4J, LightLLM, Booking Activities, and TeamCity based on exposure and privilege. The reported Pentagon data theft, MetaMask incident, McMinnville exposure, and RedFlick activity point to the same operational priorities: reduce unnecessary exposure, protect administrative paths, monitor identity and service activity, and preserve evidence when suspicious behavior appears.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

CISA KEV additions this week#

CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest. Source: CISA KEV catalog.

All KEV additions by date

Last verified: 2026-10-01

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.