Published on October 1, 2026

[CVE-2026-76504] Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Actively Exploited in the Wild


Severity

Critical

Detail

Cisco has disclosed a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, the vulnerability is being actively exploited in the wild and could allow an unauthenticated remote attacker to gain administrator-level access to vulnerable systems.

The vulnerability exists in the API session-based authentication management component of Cisco Catalyst SD-WAN Manager and is caused by improper handling of URI encoding in HTTP requests. An attacker can send a specially crafted HTTP request to bypass an authentication rule protecting a specific API endpoint and obtain access with administrator privileges.

Successful exploitation could provide an attacker with full administrative access to the SD-WAN management platform, enabling unauthorized network configuration changes, access to managed infrastructure, credential exposure, and potential compromise of enterprise-wide network environments. Cisco has confirmed active exploitation of the vulnerability and strongly recommends that affected organizations apply security updates immediately.

CVE IDSummarySeverity
CVE-2026-76504An authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain administrator-level access through crafted HTTP requests.9.8 (Critical)

Affected Products

The vulnerability affects:

  • Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage)
  • All deployments are affected regardless of system configuration.

Recommendation

Organizations should implement the following measures immediately to reduce the risk of exploitation:

  • Upgrade Cisco Catalyst SD-WAN Manager to a fixed release as soon as possible.
  • Review SD-WAN Manager logs for indicators of compromise and unauthorized access attempts.
  • Restrict access to SD-WAN Manager from the public internet.
  • Allow management access only from trusted administrative hosts and networks.
  • Place SD-WAN management components behind firewalls or other network filtering devices.
  • If compromise is suspected, collect an admin-tech file and open a Cisco TAC case for assistance.

Source

https://cybersecuritynews.com/cisco-sd-wan-manager-0-day-flaw/

https://nvd.nist.gov/vuln/detail/cve-2026-76504