Cisco Catalyst SD-WAN Manager Hit by Critical Authentication Bypass Vulnerability
Cisco disclosed a critical authentication bypass vulnerability in its Catalyst SD-WAN Manager on September 30, 2026. The flaw, tracked as CVE-2026-76504, affects the management plane for Cisco Software-Defined Wide Area Network (SD-WAN) deployments. A remote threat actor can send a specially crafted HTTP request that bypasses authentication checks and gains administrator-level access to the affected API endpoint.
The vulnerability provides administrator-level access to the affected API; administrative access to SD-WAN Manager allows a threat actor to interact with trusted management functions authorized to make changes throughout the SD-WAN environment. In many environments, unauthorized administrative access could allow modification of routing policies, network segmentation rules, device configurations, and site connectivity settings.
Organizations exposing Cisco Catalyst SD-WAN Manager to the internet face the highest risk because exploitation requires neither credentials nor user interaction. To reduce risk, organizations should identify exposed SD-WAN Manager deployments and prioritize remediation by applying relevant software updates, limiting access to trusted management networks, and restricting administrative interfaces to approved hosts.