Cisco SD-WAN Manager Zero-Day CVE-2026-76504 Grants Unauthenticated Admin API Access
TL;DR what: Cisco disclosed on September 30 that attackers are exploiting CVE-2026-76504, a URI-encoding flaw in Catalyst SD-WAN Manager that bypasses API authentication. impact: An unauthenticated attacker who can reach the Manager API can act as the admin user, whose default netadmin role can perform every operation on the device and the SD-WAN fabric it controls. fix: Cisco has fixed releases…
Cisco disclosed a critical zero-day vulnerability on September 30 affecting its Catalyst SD-WAN Manager. This vulnerability, CVE-2026-76504, involves a URI-encoding flaw in the SD-WAN Manager API that allows unauthenticated attackers to bypass authentication and gain full administrative access to the device and the SD-WAN fabric it controls.
The admin user, which has default netadmin privileges, can perform any operation on the affected device. There is no workaround for this vulnerability, and Cisco advises restricting access to the Manager API to trusted hosts until the affected devices are upgraded. Fixed releases are available, but they are not cumulative with earlier bug patches.
Any device exposed to the internet is at risk until patched. The vulnerability was confirmed active in September 2026, with no details on how many customers were affected or what actions were taken once inside.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.