Critical Cisco Vulnerability Allows Hackers to Gain Administrator Access
Cisco Systems has released emergency security updates for its Catalyst SD-WAN Manager software after confirming that hackers are actively exploiting a critical vulnerability. The flaw, tracked as CVE-2026-76504, allows attackers to bypass authentication and gain administrator-level access to affected systems without valid login credentials.
The vulnerability affects Catalyst SD-WAN Manager regardless of system configuration and can be exploited remotely, meaning no existing account or special access permissions are required. An attacker can manipulate encoded characters in certain web requests to create a request that bypasses an authentication rule protecting a particular API endpoint.
Cisco has released software updates addressing the vulnerability across multiple supported Catalyst SD-WAN software versions. Customers running affected installations have been advised to upgrade to a fixed release, but no workaround completely addresses the security flaw.