Cisco has released an emergency security advisory for a critical, actively exploited zero-day vulnerability in its Cisco Catalyst SD-WAN Manager. The vulnerability, tracked as CVE-2026-76504, is an authentication bypass flaw with a CVSS score of 9.8 (Critical). It allows an unauthenticated, remote attacker to gain administrative privileges on an affected system by sending a crafted HTTP request. Cisco's Product Security Incident Response Team (PSIRT) confirmed active exploitation in the wild. In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch. There are no workarounds, and all organizations are urged to apply the available software updates immediately.
CVE-2026-76504 stems from the improper handling of URI encoding in HTTP requests sent to the API of a Cisco Catalyst SD-WAN Manager instance. An attacker can craft a specific HTTP request with manipulated URI encoding to bypass the system's authentication and authorization checks.
A successful exploit grants the attacker the same privileges as the admin user, which by default provides complete control over the SD-WAN fabric. This includes the ability to view, modify, or delete configurations, monitor traffic, and potentially pivot to other network devices managed by the SD-WAN Manager.
The vulnerability affects the following releases of Cisco Catalyst SD-WAN Manager:
Any organization utilizing these versions, especially if the management interface is exposed to the internet, is at immediate risk of compromise.
Cisco PSIRT discovered the exploitation while investigating a customer support case in September 2026. The active, in-the-wild exploitation demonstrates that threat actors have developed a reliable method to leverage this flaw. The low complexity of the exploit means that once technical details are widely disseminated, a significant increase in attacks from various actors is highly probable. CISA's inclusion of CVE-2026-76504 in the KEV catalog on September 30, 2026, reinforces the severity and active threat posed by this vulnerability.
The impact of a successful exploit is severe. Gaining administrative control over the Catalyst SD-WAN Manager effectively gives an attacker the "keys to the kingdom" for an organization's wide area network. An attacker could:
For any organization reliant on its WAN for business operations, a compromise of the central management plane represents a critical business continuity and security risk.
Security teams may want to hunt for the following patterns to identify potential exploitation attempts:
%2e for dot, %2f for slash, or other non-standard encoding in web server logs.Organizations should focus on identifying signs of compromise and ensuring a swift response.
There are no workarounds for this vulnerability. Patching is mandatory.
Applying the vendor patch is the only way to remediate this vulnerability. There are no workarounds.
Mapped D3FEND Techniques:
Restricting network access to the management interface of the SD-WAN Manager significantly reduces the attack surface.
Mapped D3FEND Techniques:
Given the critical severity, active exploitation, and lack of workarounds, the immediate application of Cisco's provided software updates is mandatory. Organizations must identify all vulnerable Cisco Catalyst SD-WAN Manager instances within their environment. The patching process should be treated as an emergency change, prioritizing any internet-facing managers first. After applying the update, administrators must verify the new software version is correctly installed and the system is no longer vulnerable. This action is the only definitive way to prevent exploitation of CVE-2026-76504.
As a critical compensating control, organizations must implement strict inbound traffic filtering for their Cisco Catalyst SD-WAN Manager interfaces. The management plane should never be exposed directly to the public internet. Access should be restricted via firewall rules to a small, well-defined set of trusted IP addresses, such as corporate VPNs or dedicated administrative jump hosts. This practice of network hardening dramatically reduces the attack surface, making it significantly harder for a remote, unauthenticated attacker to even reach the vulnerable API endpoint. This control should be implemented immediately, even before patching is complete, to provide an initial layer of defense.
In the context of the SD-WAN Manager, this translates to rigorous monitoring of all administrative accounts and system configurations. Security teams should assume that any internet-facing, unpatched systems have been compromised. A thorough audit of all user accounts, especially those with 'admin' privileges, is necessary to identify any unauthorized accounts created by attackers. Furthermore, all system and network configurations should be reviewed against a known-good baseline to detect malicious modifications, such as altered routing policies or new firewall rules designed to facilitate further attacks. Alerts should be configured for any administrative login from an unrecognized IP or any configuration change made outside of a standard maintenance window.
Cisco releases a security advisory for CVE-2026-76504 after discovering active exploitation.
CISA adds CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) Catalog.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.