Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Exploited in Attacks (CVE-2026-76504)
Attackers are exploiting a critical Cisco Catalyst SD-WAN Manager authentication bypass, CVE-2026-76504.
Cisco disclosed CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager API session handling caused by improper URI encoding. An unauthenticated remote attacker can send a crafted HTTP request and gain administrator access. Cisco and CISA say the flaw is being exploited; CISA added it to the Known Exploited Vulnerabilities catalog with a patch deadline of October 3, 2026. Fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1, plus Cisco-managed SD-WAN Cloud 20.15.605.
- Unauthenticated remote attackers can obtain administrator privileges.
- Improper URI encoding lets crafted API requests bypass authentication.
- CISA KEV entry requires patching before October 3, 2026.
- All Catalyst SD-WAN Manager configurations are affected.
- Qualys QID 317933 detects vulnerable assets.
Vulnerabilities mentionedAll →
- CVE-2026-765049.82%Unauthenticated admin API auth bypass in Cisco Catalyst SD-WAN Managerpublished · Cisco Catalyst SD-WAN Manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article321 words · extracted from threatprotect.qualys.com · click to collapse
Cisco released a security advisory addressing a critical vulnerability affecting the Cisco Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to access an affected system with admin privileges.
Cisco mentioned in their advisory that they are aware of the vulnerability being exploited. CISA also acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerability before October 3, 2026.
Cisco Catalyst SD-WAN Manager is a centralized network management system (NMS) that provides a single pane of glass for configuring, monitoring, and troubleshooting an entire SD-WAN fabric. It serves as the orchestration and management plane of the Cisco Catalyst SD-WAN architecture.
Vulnerability Details
This vulnerability in the API-based session authentication management of Cisco Catalyst SD-WAN Manager stems from improper URI encoding in an HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system’s API. Successful exploitation of the vulnerability may allow an attacker to bypass an authentication rule that is intended to restrict access to a specific API endpoint.
Affected and Patched Versions
These vulnerabilities affect all Cisco Catalyst SD-WAN Manager, regardless of device configuration.
| Cisco Catalyst SD-WAN Software Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco has also addressed this vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605, a cloud-based release. No user action is required. Customers can determine the current remediation status or software version by using the Help function in the service GUI.
Customers can refer to the Cisco Security Advisory (cisco-sa-sdwan-webauth-xr8beuuU) for information about the vulnerability.
Qualys Detection
Qualys customers can scan their devices with QID 317933 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.