Cisco says attackers are exploiting an unauthenticated API authentication bypass that grants admin-user access to Catalyst SD-WAN Manager, with no workaround available.
What changed
Cisco disclosed CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager, and confirmed active exploitation. Crafted URI encoding can bypass an API authentication rule and provide admin-user API access. Cisco published CVE-2026-76504 on 30 September 2026 and said its PSIRT became aware of active exploitation during September 2026.
Public record through 2026-10-01. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →
What We Publish / What We Sell
D
Free · Public
The Daily
Five evidence-backed selections for security leaders, every weekday.
Scores are Security.io editorial assessments from 0–100, not vendor severity metrics. Exposure reflects deployment reach and internet accessibility; urgency reflects active exploitation and remediation constraints; business consequence reflects control-plane privilege and possible fabric-wide impact. Exposure: 88. Urgency: 98. Business consequence: 93. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial scoring based on control-plane privilege, confirmed exploitation, remediation constraints and potential business impact.