Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in real attacks

What happened
According to Cisco, CVE-2026-76504 (the public catalogue number for a specific software flaw) is being actively exploited in the wild; Cisco PSIRT became aware of the activity in September 2026. The vulnerability affects the product regardless of system configuration, and Cisco has not provided a workaround, however vendor supplied updates are available. Cisco is a networking hardware and telecommunications company based in San Jose, and its products and services include network switches and wireless access points.
Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API (the interface one piece of software uses to talk to another) authentication bypass vulnerability affecting Cisco Catalyst SD-WAN (software-defined networking in a wide area network) Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ).
An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. Cisco Catalyst SD-WAN Manager systems with ports exposed to the internet are at risk of compromise.
Sources & evidence
- Rapid7 Blog Primary / official
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) ↗
https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504