CVE-2026-76504 is a critical (CVSS 9.8) authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager's API layer, caused by improper URI/hex encoding handling (CWE-177) that allows unauthenticated remote attackers to bypass authentication and gain admin-level API access. Exploitation is trivially simple β a crafted HTTP request is sufficient β requires no credentials or user interaction, and is actively being exploited in the wild as confirmed by Cisco PSIRT in September 2026. SD-WAN Manager is a network management plane component that is frequently exposed to the internet or reachable from semi-trusted networks, making this a severe and immediate threat to enterprise network infrastructure.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-30
Added to CISA KEV: 2026-09-30 0 DAY BETWEEN CVE AND KEV
CVE-2026-76504 is a critical authentication bypass vulnerability affecting the API session-based authentication management of Cisco Catalyst SD-WAN Manager. The flaw stems from improper handling of URI encoding in HTTP requests, which allows an unauthenticated, remote attacker to manipulate requests to bypass security rules. This vulnerability is significant because it enables unauthorized actors to gain administrative access to affected systems, posing a severe threat to the integrity and confidentiality of enterprise network infrastructure.
According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the activity in September 2026. Cisco ...
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. ... CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the staβ¦
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, whichβ¦
Attackers are exploiting CVE-2026-76504 to access Cisco SD-WAN Manager APIs as admin without credentials; fixed releases are available.
Cisco TAC cases should be opened as a Severity 3 with the CVE-ID CVE-2026-76504 in the title. Before opening a new TAC case, customers are ...