Cisco SD-WAN Flaw Lets Attackers Gain Admin Access Without a Password
A critical vulnerability has been discovered in Cisco's SD-WAN Manager software, allowing an attacker to gain admin-level access without a password. The flaw, tracked as CVE-2026-76504, was added to the U.S. government's most urgent patch list and has a CVSS score of 9.8 out of 10. Multiple security vendors have confirmed that the bug is being actively exploited in the wild.
The vulnerability resides in the API session-authentication handling of Catalyst SD-WAN Manager, which provides centralized control over wide-area networks across branch offices, data centers, and cloud sites. An attacker can send a specially crafted HTTP request to bypass authentication rules and gain access to sensitive API endpoints.
Cisco has released patches for nearly every actively supported release branch, but administrators running older versions will need to upgrade to stay secure. The U.S. government's Cybersecurity and Infrastructure Security Agency (CISA) has set a federal remediation deadline of October 3, 2026, which is the same day this story is being published.
CISA's compressed deadlines for network-edge device vulnerabilities have become a pattern in 2026, with multiple instances of unauthenticated access to management-plane APIs and active exploitation within days of disclosure.