« All news

AlertCritical

Cisco patches a critical Catalyst SD-WAN Manager flaw that grants admin access without credentials

Cisco has issued an advisory for CVE-2026-76504, a critical flaw (CVSS 9.8) in the Catalyst SD-WAN Manager API that lets an unauthenticated remote attacker access the system with administrator privileges. A software update is available, but there is no workaround.

What happened

On 30 September 2026 Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU, describing an API authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage). The issue, tracked as CVE-2026-76504, carries a CVSS base score of 9.8, placing it in the critical range.

According to the Cisco advisory, the root cause lies in the API's session-based authentication management: the system mishandles URI encoding in HTTP requests, allowing a request to bypass the authentication rule that protects a specific API endpoint. Sending a single crafted HTTP request is enough to gain API access as the admin user, with no credentials and no user interaction required.

The details come from the vendor advisory; NVD has not published the entry yet.

Who is affected

Cisco states that the vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration. The advisory's Fixed Software section is the reference for which releases are vulnerable and which ones to upgrade to.

Exposure is highest for on-premises deployments reachable from the internet. For Cisco Catalyst SD-WAN Cloud Hosted environments, the access-restriction mitigation has already been deployed by Cisco.

Exploitation status

The vulnerability is not listed in CISA's KEV catalogue and has no EPSS score yet, so there is no public evidence of active exploitation. Even so, Cisco has published indicators of compromise in the advisory, which is unusual and a good reason to treat this as a high-priority case.

What to do

Cisco warns that there are no workarounds that fix the flaw: upgrading to a fixed release is the only remediation. Recommended steps:

Affected technologies

Cisco Catalyst SD-WAN Manager

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-76504Critical (9.8)⚠ Active exploitation9/30/2026Analyzed

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.