Cisco Catalyst SD-WAN Manager Hit by Critical API Bypass Vulnerability
Cisco has issued a critical security advisory for CVE-2026-76504, an API authentication bypass vulnerability in its Catalyst SD-WAN Manager. The flaw allows unauthenticated attackers to gain access to the API with admin privileges.
The vulnerability affects all Cisco Catalyst SD-WAN Manager systems, regardless of configuration, and has been actively exploited in the wild since September 2026.
Cisco has released software updates that remediate the issue, but recommends upgrading to a fixed release on an emergency basis. In addition, it advises customers to restrict access to known hosts and protect control components behind a filtering device.