CVE-2026-76504
CVSS 9.8 CRITICAL: a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…
Vulnerabilities & Exploits · Web App Attack
Cisco says attackers are already exploiting CVE-2026-76504 in Catalyst SD-WAN Manager, turning a critical authentication-bypass bug into an active risk for SD-WAN management planes. The issue affects multiple 20.x and 26.x release lines.
The flaw sits in how the product handles URI encoding: an encoded path can be treated as a different, unauthenticated route before the login check fully applies, letting a remote attacker reach admin APIs without credentials. Cisco points to anomalous `j_security_check` requests and `viptela-reserved-*` accounts as signs the bypass may have been used.
If Catalyst SD-WAN Manager fronts network control for your environment, this is exposure on the administrative layer itself, not just on one web endpoint. A patch closes the bug, but any already-abused admin access or configuration change would live beyond the fix until the logs and accounts are understood.
5 sources · 2h ago
CVSS 9.8 CRITICAL: a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…
The Hacker News
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting CVE-2026-76504 to access Cisco SD-WAN Manager APIs as admin without credentials; fixed releases are available.
originalRapid7
Critical Cisco Catalyst Sd Wan Manager API Authentication Bypass Exploited in the Wild CVE-2026-76504
On September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager.
originalNCSC-NL Advisories
Kwetsbaarheid verholpen in Cisco Catalyst SD-WAN Manager
Cisco heeft een kwetsbaarheid verholpen in Cisco Catalyst SD-WAN Manager.
originalPart of the PlainSec briefing for 2026-09-30
Every edition of this story: Cisco SD-WAN Manager Auth Bypass Is Being Exploited