Summary
- CVE-2026-76504 affects API session-based authentication in Catalyst SD-WAN Manager.
- Successful exploitation can provide an unauthenticated attacker with admin-level API access.
- Cisco says active exploitation was identified in September and no workaround is available.
Cisco has disclosed a critical authentication-bypass vulnerability in Catalyst SD-WAN Manager that is being actively exploited and can give a remote unauthenticated attacker access with administrator privileges.
Cisco assigned CVE-2026-76504 a CVSS score of 9.8 and released software updates for affected systems. There is no workaround.
The flaw sits in API session-based authentication. Cisco says improper handling of URI encoding in an HTTP request can bypass an authentication rule protecting a specific API endpoint. A crafted request can then provide access to the API as the admin user.
Cisco’s Product Security Incident Response Team became aware of active exploitation in September and is urging customers to upgrade to a fixed release.
The confirmation of exploitation changes the exposure from a theoretical patching issue into an active incident risk. An internet-reachable management interface already occupies a sensitive position; evidence that attackers are using the flaw removes the assumption that remediation can simply be left to a normal maintenance cycle.
SD-WAN management systems orchestrate connectivity and policy across distributed networks. Depending on the deployment, the management layer can expose topology information, device configuration, administrative functions, and trust relationships needed to control branch and remote-site connectivity.
Administrator access does not establish that every downstream device or workload is compromised, and Cisco’s advisory is not evidence that all vulnerable customers have been breached. It does, however, provide a route into an administrative plane intended to influence substantial parts of a network.
Cisco says systems exposed to the internet are at risk and provides indicators that customers can assess against normal network activity. Some indicators may also appear during legitimate operations, meaning they are not proof of compromise on their own.
The incident adds to a wider concentration of exploitation around edge and infrastructure products. Attackers increasingly target gateways, VPN systems, firewalls, application-delivery infrastructure, and management services that sit outside conventional endpoint monitoring while providing privileged access when compromised.
Those products can also be harder to patch quickly. Network infrastructure frequently requires coordinated maintenance because an upgrade can affect connectivity across sites, creating tension between immediate remediation and availability.
For distributed enterprises, SD-WAN centralises control precisely because that simplifies management. The same centralisation increases the consequence of a management-plane compromise, placing the vulnerability at the intersection of patching, privileged access, network architecture, and operational resilience.
Cisco has not attributed the activity to a named attacker or disclosed how broadly the vulnerability has been exploited. Confirmation of exploitation therefore establishes the existence of hostile use without resolving the scale, objectives, or post-compromise activity.
Customers concerned about previous exposure also face the distinction between remediation and investigation. Installing a fixed version closes the known authentication bypass, but organisations with evidence of suspicious activity still need to determine whether administrator access was obtained before the upgrade.
CVE-2026-76504 is therefore no longer simply a critical network vulnerability awaiting patching. Cisco’s confirmation of exploitation makes historic exposure and signs of previous administrative access part of the assessment.





