Active Exploitation of Vulnerability in Cisco Catalyst SD-WAN Manager
6 October 2026
Attackers are exploiting a critical vulnerability in Cisco Catalyst SD-WAN Manager to bypass authentication and gain admin access. Patch immediately.
Background
Cisco has released security updates to address a critical vulnerability (CVE-2026-76504) affecting Cisco Catalyst SD-WAN Manager. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Impact
Due to improper handling of URI encoding in an HTTP request within the API session-based authentication management of Cisco Catalyst SD-WAN Manager, an unauthenticated, remote attacker could send a crafted HTTP request to bypass an authentication rule intended to restrict access to a specific API endpoint. A successful exploit could allow the attacker to bypass authentication and gain access to the API with the privileges of the admin user.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects the following products:
Cisco Catalyst SD-WAN Manager versions before 20.9.10.1
Cisco Catalyst SD-WAN Manager versions 20.12 to before 20.12.8.2
Cisco Catalyst SD-WAN Manager versions 20.15 to before 20.15.6.1
Cisco Catalyst SD-WAN Manager versions 20.18 to before 20.18.4.1
Cisco Catalyst SD-WAN Manager versions 26.1 to before 26.1.2.1
Cisco Catalyst SD-WAN Manager version 26.2
Users and administrators should refer to the vendor's advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
