Yesterday Cisco published an advisory for Catalyst SD-WAN Manager, and CISA added it to the known-exploited catalog the same day. Cisco's sentence: an unauthenticated attacker on the internet can reach the system with the privileges of the admin user, on any configuration, and there is no workaround. The flaw is CVE-2026-76504. Cisco scores it 9.8. Cisco says it learned of active exploitation in September and does not name an attacker or how many customers were hit. Federal civilian agencies are due Saturday, October 3. That date is in the catalog, not on CISA's alert page.
If that dashboard is yours, install the fixed release on Cisco's table: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Anything older than 20.9 has to move to a fixed release. If you cannot update today and the manager is reachable from the internet, Cisco's temporary step is to allow only known hosts. That is not a fix. Cisco-managed cloud release 20.15.605 needs no customer install; confirm the version in the Help menu. A different Cisco sentence says that internet restriction is already in place for cloud-hosted environments. Those are not the same claim. The update does not tell you whether someone already got in. If you need that answer, Cisco says open a support case titled with CVE-2026-76504 after collecting an admin-tech file. People who do not run this dashboard have nothing to install.
A separate note, not a drained wallet. MetaMask posted Wednesday that there was no immediate threat to wallets, and updated the page this morning to say there is no indication that wallets or customer funds were affected. It is exiting affected staking validators and does not hold customers' withdrawal keys. Lido calls the same event an infrastructure compromise, says those validators should be exited but not fully withdrawn by October 7, and says stETH holders do not need to act. Ignore anyone who asks for the Secret Recovery Phrase because of this headline. MetaMask says it will never ask for that phrase.