Podcast Detail

SANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10118.mp3

Podcast Logo
Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability CVE-2026-76504
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

WatchGuard AP Command Injection in Internal Management API Allows Command Execution
https://psirt.watchguard.com/CVE-2026-86102/

A Realistic Code Execution Exploit Chain in OpenBao and Vault
https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/

Building a post-quantum certificate authority with Merkle Tree Certificates
https://blog.cloudflare.com/pq-ca-with-mtcs/

My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

Podcast Transcript

 Hello and welcome to the Thursday, October 1st, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Undergraduate Certificate Program in Applied
 Cybersecurity. Well, every day is zero day these days and we
 have another one from Cisco. This one affects the Cisco
 Catalyst SD-WAN manager. It's yet another API authentication
 bypass vulnerability and according to Cisco, it's one
 of those URI encoding issues. So if you URI encode part of
 the URL and send it to the API, it won't be recognized
 properly because apparently to Cisco, URI encoding is
 something completely new that's really not worth
 testing in their critical security products. A patch has
 been made available and this vulnerability has already been
 exploited and I bet probably by highly sophisticated
 attackers because nobody else could figure out URI encoding.
 Better make sure that you double check whether or not
 you have already been compromised ahead of this
 patch being released. Another zero day but still something
 that you probably want to patch. WatchGuard release an
 update for its access points. The internal management API
 allows command execution. Doesn't state if it does
 require authentication but the same patch also fixes another
 vulnerability that actually bypasses access control. So
 that may not really be an issue in this particular case.
 Not yet exploited so you may still have a couple days to
 patch this vulnerability. And then we got a critical patch
 for HashiCorp's vault as well as for OpenBow. OpenBow is an
 open source fork of vault so no surprise that it suffers
 from similar vulnerabilities. And I think this particular
 issue was actually sort of discovered using OpenBow. Now
 this one is actually a complex vulnerability. Some of these
 vulnerabilities that yes, you know, can happen. And one of
 the root issues here is actually four different
 vulnerabilities that have sort of been chained together to
 gain then command execution. But one of the root issue here
 that sort of gets the exploit chain started is that an
 attacker is able to essentially get an authorized
 certificate using the ACME protocol. So basically a bad
 implementation of the ACME protocol gets it all started.
 And since all of these modern credential systems rely
 heavily on certificates like your Spire and Spiffy kind of
 protocols that are implemented here by OpenBow and Vault.
 Well, that then sort of gets it basically started and then
 leads over three additional steps to remote code
 execution. So definitely get this addressed, get it
 addressed quickly, given the huge importance of these
 products in security architecture. And then a great
 blog post by Cloudflare explaining how they're going
 to move forward as a certificate authority, in
 particular when it comes to post-quantum certificates. So
 with the standards now solidifying around post
 -quantum cryptography and the TLS and now certificates,
 Cloudflare is going ahead and actually starting to deploy
 some of this in their infrastructure. One of the
 challenges with post-quantum certificates is that they're
 about 40 times the size of good old fashioned non-quantum
 safe certificates. Well, they have some interesting
 solutions here that have been developed and incorporated
 into the standards or at least draft standards in part at
 this point. One of them, Merkle trees, where you no
 longer need the entire certificate being sent forth
 and back, but really sort of just proofs of presence inside
 a Merkle tree in order to verify the certificates. Well,
 interesting stuff here. Too much for this podcast, but if
 you have an hour or so, certainly worthwhile reading
 up on it to really understand how this works, because this,
 again, is going to be deployed soon by Cloudflare and likely
 others as well. Well, and this is it for today. So thanks for
 listening. Thanks for liking. Thanks for subscribing to this
 podcast and talk to you again tomorrow. Bye.