Cisco Warns of Active Exploitation of Critical SD-WAN Manager Vulnerability
Cisco Systems has warned of a critical zero-day vulnerability in its Catalyst SD-WAN Manager that attackers are actively exploiting to gain unauthorized access. The CVE-2026-76504 flaw allows a remote attacker with no login access to use the Manager's API as the admin user, potentially leading to compromise of managed networks.
The vulnerability, discovered by Cisco's Product Security Incident Response Team in September 2026, affects all SD-WAN Manager configurations regardless of how they are set up. The flaw is caused by mishandling URI encoding in an HTTP request, allowing a crafted request to bypass authentication rules and access sensitive areas of the system.
Cisco has released fixed releases for affected versions of its SD-WAN Manager, but advises customers to restrict access to their on-prem Managers from unsecured networks until they can upgrade. The company's hardening guide also recommends that administrative interfaces should not be exposed directly to the internet.