« All news

Follow-up · active exploitationCritical

CISA confirms active exploitation of the critical Cisco Catalyst SD-WAN Manager flaw (CVE-2026-76504)

CISA has added the critical authentication bypass in the Cisco Catalyst SD-WAN Manager API to its KEV catalog, with a federal remediation deadline of 3 October 2026. Any organisation running this platform, especially if internet-facing, should patch immediately and hunt for indicators of compromise.

What happened

This is a follow-up to the Cisco Catalyst SD-WAN Manager vulnerability published earlier today, 30 September 2026. What is new is that CISA has added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog, meaning real-world exploitation has been confirmed. US federal agencies have until 3 October 2026 to remediate, a very short window that reflects the urgency of the case.

The flaw carries a CVSS score of 9.8 (critical) and allows an unauthenticated, remote attacker to access the system with the privileges of the admin user. According to Cisco's advisory, the root cause is improper handling of URI encoding in HTTP requests, which lets a request bypass the authentication rule protecting a specific API endpoint.

Who is affected

Cisco's advisory states that the vulnerability affects Cisco Catalyst SD-WAN Manager (vManage) regardless of system configuration. The highest risk is for on-premises deployments with ports reachable from the internet. For Cisco Catalyst SD-WAN Cloud Hosted environments, the vendor says the mitigation has already been deployed.

The details come from the vendor advisory (Cisco PSIRT); NVD has not published the CVE record yet. There is no EPSS score for this flaw, but with it now in KEV the theoretical probability is beside the point: exploitation is already happening.

What to do

There are no workarounds that fix the issue: the only remediation is upgrading to a fixed software release, as Cisco states in the Fixed Software section of its advisory. Beyond patching, any exposed system should be treated as potentially compromised and checked for evidence of attack.

Context

Cisco warns that some of these indicators can also appear during standard operations, so they should be assessed against your normal network posture to avoid false positives. The %6a example is illustrative only: any single encoded character in the request can be used to exploit the flaw.

SD-WAN management platforms control an entire distributed network, so admin-level access can translate into control over many branch sites. That is precisely why systems of this kind should never be published directly on the internet.

Affected technologies

Cisco Catalyst SD-WAN Manager

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-76504Critical (9.8)⚠ Active exploitation9/30/2026Analyzed

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.