Attackers Exploit Critical Cisco SD-WAN Flaw for Admin Access
Cisco has confirmed that attackers are exploiting a critical authentication bypass vulnerability in its Catalyst SD-WAN Manager system. The flaw, identified as CVE-2026-76504, allows remote attackers to run the API as the admin user without credentials.
The vulnerability carries a CVSS score of 9.8 out of 10 and affects all configurations of the SD-WAN Manager. Cisco has released fixed versions for each affected train, but there is no workaround for the flaw.
According to Cisco, companies running an internet-exposed Manager face the highest risk of compromise. The vendor advises blocking access to the system from unsecured networks until it can be upgraded.