
SANS Internet Storm Center StormCast: Critical Security Vulnerabilities in Cisco, WatchGuard, HashiCorp Vault and Cloudflare Post-Quantum Certificates
This SANS Internet Storm Center StormCast from October 1st, 2026 covers multiple critical security vulnerabilities. Cisco Catalyst SD-WAN Manager has an API authentication bypass vulnerability caused by URI encoding issues that has already been exploited in the wild, with a patch now available. WatchGuard released updates for its access points addressing a command execution vulnerability in the internal management API and an access control bypass issue, though these have not yet been exploited. HashiCorp Vault and its open source fork OpenBao have critical patches available for a complex vulnerability chain involving four separate issues, starting with a flawed ACME protocol implementation that allows unauthorized certificate acquisition and ultimately leads to remote code execution. Cloudflare published a blog post detailing their plans to deploy post-quantum certificates as a certificate authority, noting that post-quantum certificates are approximately 40 times larger than traditional certificates and discussing solutions like Merkle trees to address this challenge.