OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-76672 (CVSS 9.9)

NVD · officialPublished Sep 15, 2026Risk 50/100EPSS 0.4%

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.

CVSS
9.9
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:Low

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source