CVE-2026-76504
CVSS 9.8 CRITICAL: a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…
Vulnerabilities · 2h ago
Cisco says attackers are already exploiting CVE-2026-76504 in Catalyst SD-WAN Manager, turning a critical authentication-bypass bug into an active risk for SD-WAN management planes. The issue affects multiple 20.x and 26.x release lines.
The flaw sits in how the product handles URI encoding: an encoded path can be treated as a different, unauthenticated route before the login check fully applies, letting a remote attacker reach admin APIs without credentials. Cisco points to anomalous `j_security_check` requests and `viptela-reserved-*` accounts as signs the bypass may have been used.
If Catalyst SD-WAN Manager fronts network control for your environment, this is exposure on the administrative layer itself, not just on one web endpoint. A patch closes the bug, but any already-abused admin access or configuration change would live beyond the fix until the logs and accounts are understood.
CVSS 9.8 CRITICAL: a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…
5 sources covering this story
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting CVE-2026-76504 to access Cisco SD-WAN Manager APIs as admin without credentials; fixed releases are available.
On September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager.
Kwetsbaarheid verholpen in Cisco Catalyst SD-WAN Manager
Cisco heeft een kwetsbaarheid verholpen in Cisco Catalyst SD-WAN Manager.
Cisco: rilevato sfruttamento in rete di una vulnerabilità in Catalyst SD-WAN Manager
Cisco ha rilevato lo sfruttamento in rete di una vulnerabilità critica, identificata tramite la CVE-2026-76504, in Cisco Catalyst SD-WAN Manager, soluzione per la gestione di ambienti SD-WAN.
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
Part of the PlainSec briefing for 2026-09-30