Published on October 1, 2026
[CVE-2026-76504] Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Actively Exploited in the Wild
Severity
Critical
Detail
Cisco has disclosed a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, the vulnerability is being actively exploited in the wild and could allow an unauthenticated remote attacker to gain administrator-level access to vulnerable systems.
The vulnerability exists in the API session-based authentication management component of Cisco Catalyst SD-WAN Manager and is caused by improper handling of URI encoding in HTTP requests. An attacker can send a specially crafted HTTP request to bypass an authentication rule protecting a specific API endpoint and obtain access with administrator privileges.
Successful exploitation could provide an attacker with full administrative access to the SD-WAN management platform, enabling unauthorized network configuration changes, access to managed infrastructure, credential exposure, and potential compromise of enterprise-wide network environments. Cisco has confirmed active exploitation of the vulnerability and strongly recommends that affected organizations apply security updates immediately.
| CVE ID | Summary | Severity |
| CVE-2026-76504 | An authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain administrator-level access through crafted HTTP requests. | 9.8 (Critical) |
Affected Products
The vulnerability affects:
- Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage)
- All deployments are affected regardless of system configuration.
Recommendation
Organizations should implement the following measures immediately to reduce the risk of exploitation:
- Upgrade Cisco Catalyst SD-WAN Manager to a fixed release as soon as possible.
- Review SD-WAN Manager logs for indicators of compromise and unauthorized access attempts.
- Restrict access to SD-WAN Manager from the public internet.
- Allow management access only from trusted administrative hosts and networks.
- Place SD-WAN management components behind firewalls or other network filtering devices.
- If compromise is suspected, collect an admin-tech file and open a Cisco TAC case for assistance.
Source
https://cybersecuritynews.com/cisco-sd-wan-manager-0-day-flaw/
