Cisco Catalyst SD-WAN Manager auth bypass exploited (CVE-2026-76504)
CVE-2026-76504
CVE-2026-76504: Cisco Catalyst SD-WAN Manager unauthenticated API auth bypass grants admin access (CVSS 9.8). Apply Cisco's patch immediately.
Actively exploited in the wild - CVE-2026-76504 is a critical authentication bypass in Cisco Catalyst SD-WAN Manager that allows an unauthenticated, remote attacker to reach a protected API endpoint with the privileges of the admin user. Cisco has released software fixes; treat any internet-facing management interface as compromised until you verify otherwise.
Overview
CVE-2026-76504 sits in the API session-based authentication layer of Cisco Catalyst SD-WAN Manager. The component mishandles URI encoding inside an HTTP request, so a crafted request can slip past an authentication rule that is supposed to guard a specific API endpoint. Because the check is bypassed rather than weakened, the attacker never needs valid credentials, a session token, or any prior foothold on the network.
The consequences are severe. An attacker who reaches the management API can operate it as the admin user, which on a SD-WAN controller means control over fabric configuration, device policies, and the overlay itself. CVSS scores it 9.8 with network attack vector, low complexity, no privileges required, and no user interaction. CISA has added it to the Known Exploited Vulnerabilities catalog, confirming real-world attacks are already underway.
Impact
Affected organizations should assume that an exposed Cisco Catalyst SD-WAN Manager instance may already have been accessed. Successful exploitation yields full administrative API access, enabling configuration changes, credential and policy manipulation, and potential lateral movement into managed edge devices across the SD-WAN fabric. This is a controller-plane compromise, not a single-host incident.
Remediation and Mitigation
- Apply the fixed Cisco software release for your Catalyst SD-WAN Manager version as soon as it is available in your maintenance window.
- Do not expose the management interface to the internet. Restrict API and GUI access to trusted management networks, jump hosts, or VPN.
- Audit API and admin logs for anomalous requests containing unusual percent-encoding or traversal-style URI sequences.
- Rotate admin credentials and API tokens if you cannot rule out prior exploitation, and review recent configuration changes for unauthorized edits.
- Track CISA KEV remediation deadlines, since federal and many regulated environments now face mandatory timelines.
Cisco has a long history of exploited edge and management-plane bugs, from the Cisco ISE zero-day authentication bypass to the Secure Email Gateway flaw that granted root command execution and the FMC bugs used to deploy Qilin ransomware. Attackers clearly treat Cisco management interfaces as high-value initial access, and the same pattern shows up in broader campaigns such as the University of San Francisco ransomware claim.
Security Insight
An authentication rule that can be defeated by request encoding is not an authentication boundary at all, and CVE-2026-76504 shows how a normalization gap in one API handler can collapse the entire access model of a controller. For Cisco, this is the latest entry in a recurring theme: management and edge appliances patched under active attack, with KEV listing arriving before many customers have upgraded. The lesson for defenders is to treat SD-WAN controllers as tier-zero infrastructure, minimize their internet exposure, and monitor them as closely as domain controllers.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listin...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate ...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes eac...
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37....