CVE-2026-76504(cisco / catalyst_sd-wan_manager)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 43 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-10-03. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-177

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_sd-wan_manager

Threat summary

  • 94 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 51 mentions (2026-09-30); latest day: 43
  • 94 total mentions across 2 days

Affected systems

Vendors
Products
catalyst_sd-wan_manager

1 version affected across 1 product

Deep dive

Activity timeline94 mentions / 2d
013263851Mentions · 2026-09-30: 51Mentions · 2026-10-01: 4309-3010-01
Referenced assets50 URLs
By indicator
Full discourse20 posts
  • The Hacker News@TheHackersNews

    ‼️ WARNING - Cisco says attackers are exploiting a critical SD-WAN Manager authentication bypass. CVE-2026-76504 lets a remote attacker access the Manager API as admin without credentials. Cisco has fixes, no workaround, and log checks for suspicious activity. Read: https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html

    62001071326.8K
    2.4M followersView on X
  • CISA Cyber@CISACyber

    🛡️ We added Cisco Catalyst SD-WAN Manager hex encoding vulnerability CVE-2026-76504 to the KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/kFiFYUHGCt

    21814288.1K
    303.0K followersView on X
  • Dark Web Informer@DarkWebInformer

    🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited CVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager. The flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges. ⠀ The vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration. Cisco became aware of active exploitation in September after investigating a support case. ⠀ There are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.

    2111421210.2K
    240.9K followersView on X
  • Ryan Dewhurst@ethicalhack3r

    Cisco Catalyst SD-WAN Manager API Authentication Bypass (CVE-2026-76504) advisory has just been released, including IoCs. POST /%6a_security_check 🤯 Added to @PrevidianCyber KEV catalog. Honeypots up and monitors in place. https://t.co/dXehJ3zxeX

    46031121.5K
    21.2K followersView on X
  • Horizon3.ai@Horizon3ai

    An unauthenticated attacker can now bypass API authentication in Cisco Catalyst SD-WAN Manager to gain API access with admin privileges. Successful exploitation of CVE-2026-76504 (CVSS 9.8) grants admin-level access to control your entire SD-WAN fabric: configuration, policies, and all. What makes this P0: 🔴 Actively exploited in real attacks 🔴 CISA added it to the Known Exploited Vulnerabilities list 🔴 Affects all on-premises deployments Affected NodeZero Rapid Response customers have been proactively assessed for exposure and alerted. This is a drop everything and fix now situation.

    1801931.6K
    3.0K followersView on X
  • Rapid7@rapid7

    🚨 On 9/30/26, #Cisco published a security advisory for CVE-2026-76504 – a critical API authentication bypass vuln. affecting Cisco Catalyst SD-WAN Manager. Find mitigation guidance and more in our blog: https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504/ https://t.co/Czv7x2IE2M

    01101553.5K
    126.0K followersView on X
  • The Hacker News@TheHackersNews

    🛑 An actively exploited Cisco SD-WAN flaw can give unauthenticated attackers admin-level API access. CISA has added CVE-2026-76504 to its KEV catalog. Federal agencies have until Oct. 3 to apply the fix. What defenders should hunt for: https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html

    1401526.3K
    2.4M followersView on X
  • Defused@DefusedCyber

    🚨 We are seeing in-the-wild exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-76504 / API auth bypass) in our honeypots since Sep 30 UTC, about seven hours after Cisco's advisory. Attackers are hex-encode the login path (/%6a_security_check) to slip past the auth rule and reach the admin API. Source IPs and the full indicators are available on Defused Radar. http://console.defusedcyber.com/signup

    021124977
    7.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISCO SD-WAN MANAGER CVE-2026-76504 — CRITICAL AUTH BYPASS UNDER ACTIVE EXPLOIT Cisco published a security advisory on September 30, 2026 for a critical authentication bypass in Cisco Catalyst SD-WAN Manager (advisory cisco-sa-sdwan-webauth-xr8beuuU). • CVE-2026-76504 — improper URI encoding handling in API session-based authentication management • Impact: unauthenticated, remote attacker can access the API with admin privileges • Severity: CVSS 9.8 (Critical) • Affected: Cisco Catalyst SD-WAN Manager, regardless of system configuration • Exploitation: Cisco PSIRT became aware of active exploitation in September 2026 • Workarounds: none that fully address the issue; restrict untrusted/internet access to the system pending upgrade • Fixed releases (first fixed): 20.9.10.1 · 20.12.8.2 · 20.15.6.1 · 20.18.4.1 · 26.1.2.1 · 26.2.1 (earlier than 20.9: migrate) • Cisco SD-WAN Cloud (Cisco Managed) already addressed in cloud release 20.15.605 — no customer action for cloud-hosted ⚠️ Analyst Note: This is the official Cisco PSIRT advisory dated September 30, 2026 — not secondary media. Prefer the Cisco Security Advisory URL as primary. Not in CISA KEV at handoff. Internet-exposed SD-WAN Manager instances are highest priority; Cisco documents IOC patterns involving encoded j_security_check requests and viptela-reserved- service accounts. Official Cisco advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU #DDW #DarkWeb #Cisco #SDWAN #CVE202676504 #ZeroDay #ThreatIntelligence #CyberSecurity

    000935.2K
    205.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISA KEV — CISCO CATALYST SD-WAN MANAGER CVE-2026-76504 (HEX ENCODING → UNAUTH ADMIN ACCESS) CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) Catalog on September 30, 2026, based on evidence of active exploitation. • Product: Cisco Catalyst SD-WAN Manager • Issue: Hex/URI encoding vulnerability that can let an unauthenticated remote attacker access an affected system with admin privileges • Severity: Critical (Cisco CVSS 9.8); Cisco PSIRT aware of active exploitation in September 2026 • Federal due date: October 3, 2026 (BOD 26-04); forensic triage required • Fixes already published by Cisco: 20.9.10.1 · 20.12.8.2 · 20.15.6.1 · 20.18.4.1 · 26.1.2.1 · 26.2.1 (Cloud Hosted already remediated) ⚠️ Analyst Note: This is the CISA KEV escalation for the Cisco SD-WAN Manager zero-day already covered via Cisco’s official PSIRT advisory earlier today — not a rehash of the vendor bulletin. CISA catalogVersion 2026.09.30 (count 1730; dateReleased 2026-09-30T16:59:23Z). No separate CISA news-alert page was live at handoff time; primary source is the official KEV catalog entry plus Cisco’s advisory. Prefer CISA KEV + Cisco Security Advisory over secondary media. CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Cisco advisory (cisco-sa-sdwan-webauth-xr8beuuU): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU #DDW #DarkWeb #CISA #KEV #Cisco #SDWAN #CVE202676504 #ThreatIntelligence #CyberSecurity

    100805.0K
    205.8K followersView on X
  • kokumօtօ@__kokumoto

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)か既知の悪用された脆弱性カタログにCisco Catalyst SD-WAN ManagerのCVE-2026-76504を追加。対処期限は3日後の10/3。ランサムウェアによる悪用は不知。HTTPリクエストにおけるURIエンコーディングの処理が不適切。 https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog 差分:https://kev.kokumoto.com/#/cveId:CVE-2026-76504

    00062789
    7.8K followersView on X
  • HOL@HashgraphOnline

    Your Cisco SD-WAN Manager admin API can be reached with no login. CISA put it on the known-exploited list today. Federal due date is Oct 3. Patch on-prem Manager now. https://hol.org/blog/cve-2026-76504-cisco-sd-wan-manager-auth-bypass-kev https://t.co/qt2MPpPqyL

    03131742
    19.3K followersView on X
  • HOL@HashgraphOnline

    Anyone who can reach your Cisco SD-WAN Manager over the network can talk to the admin API without logging in. Cisco says this is being exploited. No workaround. Patch today. https://hol.org/blog/cve-2026-76504-cisco-sd-wan-manager-auth-bypass https://t.co/3PKGGe9n5U

    12230838
    19.3K followersView on X
  • ExploitGrid@exploitgrid

    🚨 CVE-2026-76504: Cisco SD-WAN Manager auth bypass. CISA added it to KEV after evidence of active exploitation. Unauthenticated attackers can bypass API authentication and gain admin access. CVSS 9.8 | KEV | No public exploit documented 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-76504

    01042182
    277 followersView on X
  • Ryx@PadhiyarRushi

    Cisco SD-WAN Manager API auth bypass. One crafted request, admin session. CVSS 9.8!!! CVE-2026-76504: Catalyst SD-WAN Manager, any config. URI encoding slips past the session rule that was supposed to lock one API endpoint. Unauth remote, admin privileges on the API. No workaround. Fixed in 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1. Advisory 30 Sep. Public checker is up. Working PoC : https://github.com/ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #NetworkSecurity #AuthBypass #KEV

    10013184
    940 followersView on X
  • Venkata Satish Guttula 🛰️@snakeyesV1

    News: Attackers exploit Cisco Catalyst SD-WAN Manager CVE-2026-76504. No login needed. They get admin API on your WAN control plane. Patch now. No workaround. Keep Manager off the public net. Check logs for encoded j_security_check hits. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

    00050183
    3.0K followersView on X
  • VulnTracker@vuln_tracker

    Cisco confirms CVE-2026-76504 is under active exploitation in Catalyst SD-WAN Manager, CVSS 9.8. A crafted URI bypasses an authentication rule, giving unauthenticated attackers full admin API access on any deployment, the fifth actively exploited SD-WAN zero-day this year. VulnTracker recommends upgrading to the fixed release immediately, Cisco has published one for every affected branch. Details: http://vulntracker.io/cves/CVE-2026-76504 #Cisco #SDWAN #CVE #InfoSec

    10040179
    783 followersView on X
  • Previdian@PrevidianCyber

    Added as a KEV to Previdian catalog. https://previdian.com/CVE-2026-76504

    11021605
    133 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Attackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. Patch now. #Cisco #SDWAN #CVE202676504 #AuthenticationBypass #ActivelyExploited #CyberSecurity https://securityonline.info/cisco-sd-wan-manager-cve-2026-76504/

    01021389
    13.0K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity

    CVE-2026-76504 Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU 『Cisco Catalyst SD-WAN ManagerのAPIセッションベース認証管理における脆弱性により、認証されていないリモート攻撃者が、管理者ユーザーの権限で影響を受けるシステムにアクセスできる可能性があります』 KEV掲載あり https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog

    00021770
    11.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_sd-wan_manager---
Appciscocatalyst_sd-wan_manager26.2--

Explore more