Cisco Patches Exploited Vulnerability in Catalyst SD-WAN Manager
Cisco has released urgent patches for a critical authentication bypass vulnerability in its Catalyst SD-WAN Manager that has been exploited in the wild.
The flaw, tracked as CVE-2026-76504 with a CVSS score of 9.8, affects the API session-based authentication mechanism and could allow remote, unauthenticated attackers to gain administrative access to a vulnerable system.
Cisco warns that all Catalyst SD-WAN Manager deployments are affected, regardless of their configuration, and there are no workarounds.
The issue resides in the improper handling of URI encoding in an HTTP request, allowing attacker requests to reach a restricted API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system, gaining access as the admin user.