By Ionut Arghire
Publication Date: 2026-10-01 08:26:00
Cisco on Wednesday rolled out urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager that has been exploited in the wild.
Tracked as CVE-2026-76504 (CVSS score of 9.8), the flaw impacts the API session-based authentication mechanism and could allow remote, unauthenticated attackers to gain administrative access to a vulnerable system.
“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company warned.
According to Cisco, the issue resides in the improper handling of URI encoding in an HTTP request, allowing attacker requests to reach a restricted API endpoint.
“An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the…


