Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

Cisco SD-WAN Manager Zero-Day CVE-2026-76504 Grants Unauthenticated Admin API Access

TL;DR what: Cisco disclosed on September 30 that attackers are exploiting CVE-2026-76504, a URI-encoding flaw in Catalyst SD-WAN Manager that bypasses API authentication.

  • Cisco reports zero-day vulnerability CVE-2026-76504 in SD-WAN Manager API.
  • Unauthenticated attackers can bypass authentication and gain full admin access.
  • Immediate patching advised to restrict API access to trusted hosts.

More from Wednesday 30 September →