Cisco security advisory (AV26-978)
CISA added Cisco Catalyst SD-WAN Manager API authentication bypass CVE-2026-76504 to the KEV catalog.
Canadian Centre for Cyber Security advisory AV26-978 says Cisco Catalyst SD-WAN Manager versions before 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1 are affected by API authentication bypass CVE-2026-76504. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on September 30, 2026. The Cyber Centre urges administrators to review Cisco's advisory and apply available updates.
- CVE-2026-76504 is an API authentication bypass in Cisco Catalyst SD-WAN Manager.
- CISA added the flaw to the KEV catalog on September 30, 2026.
- Affected builds predate 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.
Vulnerabilities mentionedAll →
- CVE-2026-765049.82%Unauthenticated admin API auth bypass in Cisco Catalyst SD-WAN Managerpublished · Cisco Catalyst SD-WAN Manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article91 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-978
Date: October 1, 2026
As of September 30, 2026, Cisco is affected by a vulnerability in the following product:
- Cisco Catalyst SD-WAN Manager
- Versions prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 et 26.2.1
On September 30, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-978