Skip to content
feed: live
>_0dayNews
cisco
● Breaking

Cisco SD-WAN Manager Auth Bypass Exploited: Patch Now

CVE-2026-76504, an authentication bypass in Cisco SD-WAN Manager rated CVSS 9.8, is under active exploitation. Federal agencies must patch by October 3.

Cisco SD-WAN Manager Auth Bypass Exploited: Patch Now
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

The patch is overdue. Cisco published a security advisory for CVE-2026-76504 on September 30 covering a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager. CISA added it to the Known Exploited Vulnerabilities catalog the same day, with a federal agency remediation deadline of October 3.

That gives you three days.

What the flaw is

SD-WAN Manager is the centralized control plane for Cisco SD-WAN deployments. It’s how network teams push configurations, monitor traffic paths, and manage connected edge devices. CVE-2026-76504 is a hex encoding flaw in the application’s HTTP request handling: an unauthenticated attacker can craft a URI that bypasses the authentication check entirely and lands with admin-level access, according to the Cisco advisory and NVD record.

Admin access to the management plane is about as bad as it gets for network infrastructure. From there, an attacker can reconfigure traffic routing, harvest credentials, and potentially reach every SD-WAN-connected branch device.

Exploitation status

CISA’s KEV listing confirms active exploitation. Rapid7’s emergency threat response and BleepingComputer both reported in-the-wild attacks as of September 30.

What to do

Cisco released fixed software with the September 30 advisory. Apply it. Federal agencies are under CISA BOD 26-04 with an October 3 deadline. If patching is not immediately possible, the advisory includes workaround guidance and Cisco’s interim mitigation steps.

If SD-WAN Manager has any exposure to untrusted networks, treat it as a same-day priority.

Context

CVE-2026-76504 fits a pattern that has been consistent through 2026: an unauthenticated bypass or RCE in a Cisco management interface, followed by active exploitation within days of disclosure. It joins Cisco ISE CVE-2026-76460 (CVSS 10.0, KEV), Cisco Secure Email Gateway CVE-2026-76461 (SQLi/RCE, KEV), and Cisco FMC CVE-2026-20079 (CVSS 10.0, exploited). If Cisco management interfaces are on your network, treat their exposure surface as an active, recurring risk.

Patch this first.

Related CVEs
  • [ CRITICAL ]CVE-2026-76504Cisco Catalyst SD-WAN Manager Authentication Bypass

Found this useful? Share it.