Cisco patches an exploited authentication bypass in Catalyst SD-WAN Manager, its fifth SD-WAN zero-day this year
The flaw gives remote, unauthenticated attackers admin access to the API. It affects every deployment and has no workaround, and CISA has added it to its exploited-vulnerabilities catalog.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
On Wednesday Cisco released urgent patches for CVE-2026-76504, a critical authentication bypass (CVSS 9.8) in Catalyst SD-WAN Manager that attackers have exploited in the wild. The product is the central management console for Cisco's software-defined wide area networks, so a compromise can hand attackers control of the network. Cisco says the flaw comes from improper handling of URI encoding in HTTP requests. A crafted request can slip past an authentication rule meant to restrict a specific API endpoint and reach the API as the admin user. All Catalyst SD-WAN Manager deployments are affected regardless of configuration, and there are no workarounds. Cisco strongly recommends upgrading to a fixed release. Cisco's product security team learned of the exploitation in September 2026 while resolving a Technical Assistance Center support case, Help Net Security reports. The company has not described the attacks but has published indicators of compromise for defenders. Help Net Security says this is the fifth time this year that Cisco has disclosed zero-day exploitation of its SD-WAN product. According to Security Affairs, the US Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog. That listing puts federal agencies under a patching deadline.