Cisco Addresses Critical Authentication Bypass Vulnerability in SD-WAN Manager (CVE-2026-76504)
Cisco has identified a critical zero-day vulnerability (CVE-2026-76504) in its SD-WAN Manager that allows remote attackers to bypass authentication and gain admin-level access without credentials. The flaw, actively exploited in the wild, requires immediate upgrades as no workaround exists and affected systems face significant compromise risks.
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.
The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a
*** END OF TRANSMISSION ***