By Zeljka Zorz
Publication Date: 2026-10-01 10:18:00
For the fifth time this year, Cisco revealed attackers have exploited a vulnerability (CVE-2026-76504) in its SD-WAN solution in zero-day attacks.
The vendor’s incident responders became aware of active exploitation of this vulnerability in September 2026, after getting pinged and resolving a Cisco Technical Assistance Center (TAC) support case.
Cisco has yet to share any details about the attacks, but it has provided indicators of compromise defenders should look for to check whether they have been targeted.
About CVE-2026-76504
CVE-2026-76504 is an API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager, the central management console for Cisco’s software-defined wide area network solution. Compromising it can give attackers control over the network.
“This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific…

