Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
Cisco says critical SD-WAN Manager zero-day CVE-2026-76504 is under active exploitation.
Cisco warned that CVE-2026-76504, a CVSS 9.8 flaw in Catalyst SD-WAN Manager, lets an unauthenticated remote attacker gain administrator API access through a crafted HTTP request that abuses URI encoding. Cisco said the bug is under active exploitation, published no workaround, and urged upgrades; cloud-hosted environments already received a mitigation. CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog, and Rapid7 advised immediate patching and compromise audits. The report also recalls last month’s actively exploited Cisco ISE flaw, CVE-2026-76460, rated CVSS 10.
- CVE-2026-76504 scores CVSS 9.8 and requires no authentication.
- Crafted HTTP requests bypass API authentication and yield admin rights.
- Cisco says there is no workaround and exploitation is active.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog.
- Cloud-hosted SD-WAN Manager already received Cisco’s mitigation.
Vulnerabilities mentionedAll →
- CVE-2026-7646010.014%Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PICpublished · Cisco Identity Services Engine (ISE) KEV PoC
Full article404 words · extracted from infosecurity-magazine.com · click to collapse
vulnerability in Cisco Catalyst SD-WAN Manager which had already been exploited in the wild.
In a security advisory published on September 30, Cisco issued a warning about CVE-2026-76504, a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager which could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
With a CVSS score of 9.8 the vulnerability is classed as critical. If it is not remediated immediately, it could result in widespread exploitation by malicious hackers, consequences of which could include data loss, system downtime or complete system takeover.
Any Cisco Catalyst SD-WAN Manager systems with ports exposed to the internet are potentially at risk of compromise.
CVE-2026-76504 Exploited in the Wild
According to Cisco, CVE-2026-76504 is already under “active exploitation” and the company “strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability”.
There are no workarounds to remediate the vulnerability without applying the security update.
The vulnerability has emerged as a result of improper handling of URI encoding in an HTTP request, which if exploited allows an unauthorised, remote attacker to bypass authentication rules via the use of a crafted HTTP request.
Exploitation could allow the attacker to gain access to the API with the permissions of an administrator.
With this functionality, an attacker could essentially compromise the whole network, allowing an unauthorized user to pivot throughout and alter and delete files and backups.
The mitigation against CVE-2026-76504 has already been deployed to Cisco Catalyst SD-WAN Cloud Hosted environments.
However, Cisco warned, “While this mitigation has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions.”
Mitigation Advice: Audit Systems, Apply Patches
In analysis of the vulnerability, Rapid7 urged organizations which use Cisco Catalyst SD-WAN Manager to upgrade to an appropriate fixed release without waiting for a regular patch cycle.
“Because active exploitation has occurred, Rapid7 strongly recommends that organizations audit affected systems for compromise,” the company said in a blog post published on October 1.
The US Cybersecurity Infrastructure and Security Agency (CISA) has added CVE-2026-76504 to its known exploited vulnerabilities (KEV) catalogue and recommended organizations to apply mitigations.
Just last month, Cisco warned customers of about active exploitation of CVE-2026-76460, a maximum severity flaw with a CVSS rating of 10 which affected its Cisco Identity Services Engine (ISE).