Cisco SD-WAN Manager Hit by Critical Vulnerability CVE-2026-76504
Cisco's Catalyst SD-WAN Manager has been hit by a critical vulnerability, CVE-2026-76504, which allows attackers to bypass authentication and access the management API with admin privileges. The flaw affects all versions of the software prior to 20.9 and is being actively exploited in the wild.
Cisco discovered the issue while investigating a customer support case and has since released fixed software for affected release trains. The company recommends upgrading systems on an emergency basis, as those with management ports reachable from the internet face the greatest risk of compromise.
Security teams are advised to review log files for suspicious activity, such as login requests from unknown IP addresses, and restrict network access to the Manager from the internet. Cisco also warns that earlier vulnerabilities in the same software have been exploited by APT groups and other attackers.