Cisco Warns of Critical Vulnerability in SD-WAN Manager Under Active Exploitation
Cisco has issued an advisory warning of attacks exploiting a critical vulnerability in its Catalyst SD-WAN Manager. The flaw, CVE-2026-76504, allows remote attackers without login access to use the Manager API as an administrator. This could grant them control over the entire network.
The bug affects all configurations and no other products are listed as affected. Cisco's Product Security Incident Response Team was made aware of active exploitation in September 2026, while handling a support case.
CVE-2026-76504 has a CVSS score of 9.8 out of 10 and is located in the part of the Manager API that handles login sessions. The Manager incorrectly handles URI encoding in an HTTP request, allowing a crafted request to bypass an authentication rule.