Cisco SD-WAN Vulnerability Grants Unauthenticated Admin Access
A critical authentication bypass vulnerability has been discovered in Cisco's SD-WAN Manager, allowing unauthenticated attackers to gain administrative access. The flaw, tracked as CVE-2026-76504, stems from improper handling of URL/URI encoding and has a CVSS score of 9.8.
Cisco confirmed active exploitation of this vulnerability in September 2026, with CISA adding it to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Federal agencies have been given until October 3, 2026, to remediate the issue.
The exploit mechanism is deceptively simple, involving a single-character substitution in a URL path that tricks the system into granting access without valid credentials. This allows attackers to gain extensive control over large-scale network infrastructure.