Handler on Duty: Xavier Mertens
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10118.mp3
Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability CVE-2026-76504
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
WatchGuard AP Command Injection in Internal Management API Allows Command Execution
https://psirt.watchguard.com/CVE-2026-86102/
A Realistic Code Execution Exploit Chain in OpenBao and Vault
https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/
Building a post-quantum certificate authority with Merkle Tree Certificates
https://blog.cloudflare.com/pq-ca-with-mtcs/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Thursday, October 1st, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Undergraduate Certificate Program in Applied Cybersecurity. Well, every day is zero day these days and we have another one from Cisco. This one affects the Cisco Catalyst SD-WAN manager. It's yet another API authentication bypass vulnerability and according to Cisco, it's one of those URI encoding issues. So if you URI encode part of the URL and send it to the API, it won't be recognized properly because apparently to Cisco, URI encoding is something completely new that's really not worth testing in their critical security products. A patch has been made available and this vulnerability has already been exploited and I bet probably by highly sophisticated attackers because nobody else could figure out URI encoding. Better make sure that you double check whether or not you have already been compromised ahead of this patch being released. Another zero day but still something that you probably want to patch. WatchGuard release an update for its access points. The internal management API allows command execution. Doesn't state if it does require authentication but the same patch also fixes another vulnerability that actually bypasses access control. So that may not really be an issue in this particular case. Not yet exploited so you may still have a couple days to patch this vulnerability. And then we got a critical patch for HashiCorp's vault as well as for OpenBow. OpenBow is an open source fork of vault so no surprise that it suffers from similar vulnerabilities. And I think this particular issue was actually sort of discovered using OpenBow. Now this one is actually a complex vulnerability. Some of these vulnerabilities that yes, you know, can happen. And one of the root issues here is actually four different vulnerabilities that have sort of been chained together to gain then command execution. But one of the root issue here that sort of gets the exploit chain started is that an attacker is able to essentially get an authorized certificate using the ACME protocol. So basically a bad implementation of the ACME protocol gets it all started. And since all of these modern credential systems rely heavily on certificates like your Spire and Spiffy kind of protocols that are implemented here by OpenBow and Vault. Well, that then sort of gets it basically started and then leads over three additional steps to remote code execution. So definitely get this addressed, get it addressed quickly, given the huge importance of these products in security architecture. And then a great blog post by Cloudflare explaining how they're going to move forward as a certificate authority, in particular when it comes to post-quantum certificates. So with the standards now solidifying around post -quantum cryptography and the TLS and now certificates, Cloudflare is going ahead and actually starting to deploy some of this in their infrastructure. One of the challenges with post-quantum certificates is that they're about 40 times the size of good old fashioned non-quantum safe certificates. Well, they have some interesting solutions here that have been developed and incorporated into the standards or at least draft standards in part at this point. One of them, Merkle trees, where you no longer need the entire certificate being sent forth and back, but really sort of just proofs of presence inside a Merkle tree in order to verify the certificates. Well, interesting stuff here. Too much for this podcast, but if you have an hour or so, certainly worthwhile reading up on it to really understand how this works, because this, again, is going to be deployed soon by Cloudflare and likely others as well. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for subscribing to this podcast and talk to you again tomorrow. Bye.





