Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
Cisco says CVE-2026-76504, a critical SD-WAN Manager API authentication bypass, is being exploited in the wild.
On September 30, 2026, Cisco disclosed CVE-2026-76504, a CVSS 9.8 API authentication bypass in Cisco Catalyst SD-WAN Manager caused by improper URL-encoding handling. An unauthenticated remote attacker can send a crafted HTTP request and reach a specific API endpoint with admin privileges. Cisco says the flaw is being actively exploited, no workaround is available, and fixed on-premises releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Managed Cisco SD-WAN Cloud release 20.15.605 is already patched, and Rapid7 urges emergency upgrades plus log review.