Cisco ships the password, the market pays the multiple
Cisco disclosed an exploited, no-workaround admin bypass in Catalyst SD-WAN Manager on 30 September [1], three weeks after its own Talos team traced live intrusions to a password shipped inside its firewall console [6]. The stock trades at 31.8 times trailing earnings for a story in which AI infrastructure is 6 percent of revenue [7].
Vincent Jiang · 3 min read
An admin door with no workaround
On 30 September Cisco told customers that attackers are already exploiting the software that runs their wide-area networks 12. CVE-2026-76504, rated 9.8, lets an unauthenticated stranger use the Catalyst SD-WAN Manager API with full admin rights by encoding one character of a login request 13. There is no workaround, the flaw surfaced through a routine support case, and CISA ordered federal agencies to patch by 3 October 123.
It is the fifth Cisco SD-WAN zero-day exploited this year, and the third critical unauthenticated authentication flaw in that product since February 12. Three weeks earlier, on 9 September, Cisco's own Talos unit traced three intrusion clusters in Secure Firewall Management Center, the console that manages customers' firewalls: Qilin ransomware operators who came in through the shipped-in password, and a crew whose tooling overlaps Russia's Sandworm 456.
A 31.8x multiple on 6 percent
The market prices Cisco as an AI stock: a 61 percent one-year return, and 31.8 times trailing earnings against 21.9 for the S&P 500 7. That premium has room for little to go wrong 7.
The filings price it otherwise. AI infrastructure delivered about $4 billion of fiscal 2026's $63.3 billion revenue, roughly 6 percent; the $7.5 billion expected this year is guidance 87. The final quarter grew 18 percent on product orders up 35 percent, and management said price rises on memory-heavy hardware added about 5 points 87.
Fiscal 2027 is guided to $72.2 billion to $73.4 billion, with growth outside AI near 10 percent against the 12 and 18 percent quarters it must lap 87. Piper Sandler cut its target to $125 in late September on concern that growth is peaking 7.
Cisco's growth kept accelerating to an 18 percent final quarter, and the guide asks for more
- Revenue
- Estimate
Data
| Revenue | |
|---|---|
| FQ1'24 | $14.67B |
| FQ2'24 | $12.79B |
| FQ3'24 | $12.7B |
| FQ4'24 | $13.64B |
| FQ1'25 | $13.84B |
| FQ2'25 | $13.99B |
| FQ3'25 | $14.15B |
| FQ4'25 | $14.67B |
| FQ1'26 | $14.88B |
| FQ2'26 | $15.35B |
| FQ3'26 | $15.84B |
| FQ4'26 | $17.25B |
| FQ1'27 guide (estimate) | $18.1B ($18.0–18.2B) |
The pattern the pledge didn't break
Cisco signed CISA's Secure by Design pledge in May 2024, which asks signers to show measurable progress within a year toward cutting default passwords; it is voluntary and unverified 6. The advisories kept landing: hard-coded credentials flagged in 2018 and 2021, an unchangeable root account in Emergency Responder in 2023, a 9.8-rated static administrator login in Smart Licensing Utility in September 2024, five static Firepower accounts a month later 6.
The record cuts both ways. Cisco names the weakness, ships fixes, publishes indicators, and a vendor that digs into its own products will find flaws 6. Scale is the uncomfortable part: since November 2021 CISA has tagged 90 Cisco vulnerabilities as exploited in the wild, seven of them abused by ransomware crews 2.
The same budget, other bidders
The payer is the enterprise or telco CISO renewing security contracts with the vendor whose own incident reports name the way in, on hardware that just took a memory-price increase 567. CISA's catalog lists 15 hard-coded or default-credential entries from 13 vendors, so the grass is not automatically greener 6.
Across the street the trade is cleaner. CrowdStrike and Palo Alto have more than doubled in six months as the AI cybersecurity trade begins, at roughly 208 and 93.5 times forward earnings, into a market Gartner sees climbing from $51.3 billion this year toward $86 billion in 2027 9. CrowdStrike posted record net new annual recurring revenue of $333 million last quarter; Palo Alto's next-generation security ARR rose 63 percent to $9.10 billion 910.
A miss is the early warning
Nothing yet ties these advisories to a lost renewal; that part is unproven. The first hard reading is the fiscal Q1 2027 report against the $18.0 billion to $18.2 billion guide, where a miss is the early warning on the full-year outlook 87.
Until then the record says: the password was in the product, and the premium is in the price.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



