πŸ”΄ CVE-2026-76504

CVE-2026-76504 is a critical (CVSS 9.8) authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager's API layer, caused by improper URI/hex encoding handling (CWE-177) that allows unauthenticated remote attackers to bypass authentication and gain admin-level API access. Exploitation is trivially simple β€” a crafted HTTP request is sufficient β€” requires no credentials or user interaction, and is actively being exploited in the wild as confirmed by Cisco PSIRT in September 2026. SD-WAN Manager is a network management plane component that is frequently exposed to the internet or reachable from semi-trusted networks, making this a severe and immediate threat to enterprise network infrastructure.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-30

Added to CISA KEV: 2026-09-30 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-30)

Summary

CVE-2026-76504 is a critical authentication bypass vulnerability affecting the API session-based authentication management of Cisco Catalyst SD-WAN Manager. The flaw stems from improper handling of URI encoding in HTTP requests, which allows an unauthenticated, remote attacker to manipulate requests to bypass security rules. This vulnerability is significant because it enables unauthorized actors to gain administrative access to affected systems, posing a severe threat to the integrity and confidentiality of enterprise network infrastructure.

Exploitation

  • Active Exploitation: The vulnerability is currently being actively exploited in the wild, with Cisco PSIRT confirming malicious activity observed in September 2026 [1].
  • Threat Actors/Campaigns: While specific threat actor names have not been publicly attributed as of late September 2026, the ongoing campaign targets enterprise deployments [2].
  • Proof-of-Concept: There are no publicly available exploit tools or proof-of-concept code detailed in current security advisories, but the exploit mechanism is being utilized by attackers [2].
  • Attack Prerequisites: This is a remote, unauthenticated attack that does not require user interaction or valid credentials to execute [3].

Affected Products & Patches

  • Affected Versions: The vulnerability affects Cisco Catalyst SD-WAN Manager. Users should consult the official Cisco Security Advisory for specific version strings and impacted configurations [5].
  • Patch Availability: Cisco has released security updates to address this vulnerability; organizations are urged to apply these patches immediately to mitigate the risk of exploitation [2][4].
  • Mitigations: There are no documented workarounds; applying the vendor-provided software update is the only effective resolution [4].

Impact

  • Access and Capability: Successful exploitation allows an attacker to gain full administrative privileges within the Cisco Catalyst SD-WAN Manager, enabling them to control or reconfigure the network management environment [3].
  • Business Risk: For internet-facing deployments, this vulnerability presents an extreme risk, as it provides an entry point for remote actors to compromise sensitive network infrastructure, potentially leading to unauthorized data access, disruption of network services, or deep-level persistent access to corporate resources [1].

Sources

  1. Critical Cisco Catalyst SD-WAN Manager API ...

    According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the activity in September 2026. Cisco ...

  2. Cisco warns of new SD-WAN zero-day exploited in attacks

    Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. ... CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the sta…

  3. CVE-2026-76504 - Cisco Catalyst SD-WAN Manager System Account ...

    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which…

  4. Cisco Warns of Attackers Exploiting Critical Authentication ...

    Attackers are exploiting CVE-2026-76504 to access Cisco SD-WAN Manager APIs as admin without credentials; fixed releases are available.

  5. Cisco Catalyst SD-WAN Manager API Authentication ...

    Cisco TAC cases should be opened as a Severity 3 with the CVE-ID CVE-2026-76504 in the title. Before opening a new TAC case, customers are ...