WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in real attacks

Detailed close-up of ethernet cables and network connections on a router, showcasing modern technology.
Illustrative photo.Photo by Pixabay on PexelsCisco logo shown for identification only; no affiliation with or endorsement of WORLDTECH is implied.

What happened

According to Cisco, CVE-2026-76504 (the public catalogue number for a specific software flaw) is being actively exploited in the wild; Cisco PSIRT became aware of the activity in September 2026. The vulnerability affects the product regardless of system configuration, and Cisco has not provided a workaround, however vendor supplied updates are available. Cisco is a networking hardware and telecommunications company based in San Jose, and its products and services include network switches and wireless access points.

Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API (the interface one piece of software uses to talk to another) authentication bypass vulnerability affecting Cisco Catalyst SD-WAN (software-defined networking in a wide area network) Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ).

An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. Cisco Catalyst SD-WAN Manager systems with ports exposed to the internet are at risk of compromise.

Sources & evidence