Cisco ships the password, the market pays the multiple

Cisco disclosed an exploited, no-workaround admin bypass in Catalyst SD-WAN Manager on 30 September [1], three weeks after its own Talos team traced live intrusions to a password shipped inside its firewall console [6]. The stock trades at 31.8 times trailing earnings for a story in which AI infrastructure is 6 percent of revenue [7].

In this storyCSCOCRWD
Vincent JiangVincent Jiang · 3 min read
Share
Chuck Robbins, Cisco's chair and chief executive, in a tuxedo against a dark blue backdrop at a Washington event
1 / 6Slide 1 of 6
Chuck Robbins, Cisco's chair and chief executive, at a Business Executives for National Security event in Washington, April 2018.

An admin door with no workaround

On 30 September Cisco told customers that attackers are already exploiting the software that runs their wide-area networks 12. CVE-2026-76504, rated 9.8, lets an unauthenticated stranger use the Catalyst SD-WAN Manager API with full admin rights by encoding one character of a login request 13. There is no workaround, the flaw surfaced through a routine support case, and CISA ordered federal agencies to patch by 3 October 123.

It is the fifth Cisco SD-WAN zero-day exploited this year, and the third critical unauthenticated authentication flaw in that product since February 12. Three weeks earlier, on 9 September, Cisco's own Talos unit traced three intrusion clusters in Secure Firewall Management Center, the console that manages customers' firewalls: Qilin ransomware operators who came in through the shipped-in password, and a crew whose tooling overlaps Russia's Sandworm 456.

A 31.8x multiple on 6 percent

The market prices Cisco as an AI stock: a 61 percent one-year return, and 31.8 times trailing earnings against 21.9 for the S&P 500 7. That premium has room for little to go wrong 7.

The filings price it otherwise. AI infrastructure delivered about $4 billion of fiscal 2026's $63.3 billion revenue, roughly 6 percent; the $7.5 billion expected this year is guidance 87. The final quarter grew 18 percent on product orders up 35 percent, and management said price rises on memory-heavy hardware added about 5 points 87.

Fiscal 2027 is guided to $72.2 billion to $73.4 billion, with growth outside AI near 10 percent against the 12 and 18 percent quarters it must lap 87. Piper Sandler cut its target to $125 in late September on concern that growth is peaking 7.

Cisco's growth kept accelerating to an 18 percent final quarter, and the guide asks for more

  • Revenue
  • Estimate
$12B$14B$16B$18B$20BFQ1'24FQ3'24FQ1'25FQ3'25FQ1'26FQ3'26FQ1'27 guide$18.1B$18.0–18.2B$17.25B
Data
Revenue
FQ1'24$14.67B
FQ2'24$12.79B
FQ3'24$12.7B
FQ4'24$13.64B
FQ1'25$13.84B
FQ2'25$13.99B
FQ3'25$14.15B
FQ4'25$14.67B
FQ1'26$14.88B
FQ2'26$15.35B
FQ3'26$15.84B
FQ4'26$17.25B
FQ1'27 guide (estimate)$18.1B ($18.0–18.2B)
Quarterly revenue, US$B, Cisco fiscal quarters. FQ1 2024 to FQ4 2026 are reported; the final point is Cisco's guidance of $18.0B to $18.2B, marked as an estimate. Sources: Sharadar quarterly fundamentals from SEC filings; Cisco Q4 FY2026 earnings release, 12 August 2026.8,11

The pattern the pledge didn't break

Cisco signed CISA's Secure by Design pledge in May 2024, which asks signers to show measurable progress within a year toward cutting default passwords; it is voluntary and unverified 6. The advisories kept landing: hard-coded credentials flagged in 2018 and 2021, an unchangeable root account in Emergency Responder in 2023, a 9.8-rated static administrator login in Smart Licensing Utility in September 2024, five static Firepower accounts a month later 6.

The record cuts both ways. Cisco names the weakness, ships fixes, publishes indicators, and a vendor that digs into its own products will find flaws 6. Scale is the uncomfortable part: since November 2021 CISA has tagged 90 Cisco vulnerabilities as exploited in the wild, seven of them abused by ransomware crews 2.

The same budget, other bidders

The payer is the enterprise or telco CISO renewing security contracts with the vendor whose own incident reports name the way in, on hardware that just took a memory-price increase 567. CISA's catalog lists 15 hard-coded or default-credential entries from 13 vendors, so the grass is not automatically greener 6.

Across the street the trade is cleaner. CrowdStrike and Palo Alto have more than doubled in six months as the AI cybersecurity trade begins, at roughly 208 and 93.5 times forward earnings, into a market Gartner sees climbing from $51.3 billion this year toward $86 billion in 2027 9. CrowdStrike posted record net new annual recurring revenue of $333 million last quarter; Palo Alto's next-generation security ARR rose 63 percent to $9.10 billion 910.

A miss is the early warning

Nothing yet ties these advisories to a lost renewal; that part is unproven. The first hard reading is the fiscal Q1 2027 report against the $18.0 billion to $18.2 billion guide, where a miss is the early warning on the full-year outlook 87.

Until then the record says: the password was in the product, and the premium is in the price.

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio