Attackers are weaponizing a brand new critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.
The vulnerability, CVE-2026-76504, allows a remote attacker with no login access to use the Manager’s API as the admin user. Fixed releases are available, and there is no workaround. It has a CVSS score of 9.8 out of 10. It’s in the part of the Manager’s API that handles login sessions.
The Manager has incorrect handling of URI encoding of an HTTP request. A crafted request can therefore bypass an authentication rule that’s meant to restrict access to a single API endpoint.
The attacker does not need any credentials to mount this attack, only the ability to send the request to the Manager’s API. Managers exposed to the Internet are vulnerable to being compromised, Cisco warned. By default, the admin user possesses the netadmin role, which is granted permissions to carry out all operations on the device.
Cisco says its Product Security Incident Response Team “became aware of active exploitation of this vulnerability” in September 2026, when the flaw was discovered by engineers at Cisco’s Technical Assistance Center read more about Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
