Cisco Warns of Critical Vulnerability in Catalyst SD-WAN Manager
Cisco has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in its Catalyst SD-WAN Manager. The flaw allows an unauthenticated remote attacker to access the management API with administrator privileges.
The issue stems from improper handling of URI encoding, classified as CWE-177: Improper Handling of URL Encoding (Hex Encoding). Inconsistent interpretation of encoded characters can allow a specially crafted HTTP request to bypass an authentication rule protecting a specific API endpoint.
Cisco has confirmed active exploitation in September 2026 and assigned the vulnerability a CVSS 3.1 score of 9.8 (Critical). CISA added it to its Known Exploited Vulnerabilities catalog on September 30, setting an October 3, 2026 remediation deadline for covered federal agencies.