CriticalCritical vulnerability
CVE-2026-76672 (CVSS 9.9)
NVD · officialPublished Sep 15, 2026Risk 50/100EPSS 0.4%
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Technical details
CVSS
9.9
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:Low
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source