Cisco Warns of Active Exploitation in Critical SD-WAN Manager Flaw
Cisco has released a security advisory warning that attackers are actively exploiting a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager.
FTMQ Security, written by our newsroom0 views

Cisco published a security advisory on September 30, 2026, warning that attackers are actively exploiting a critical vulnerability in Cisco Catalyst SD-WAN Manager. The Rapid7 Blog and The Hacker News both report that the vulnerability is tracked as CVE-2026-76504 and carries a maximum CVSSv3.1 severity score of 9.8. Infosecurity Magazine and Network World also confirmed that the flaw is being targeted under active exploitation. [1][3][4][6]
The vulnerability stems from the improper handling of URL encoding, identified as CWE-177. According to the Rapid7 Blog, an unauthenticated remote attacker can exploit this flaw by sending a specially crafted HTTP request to bypass an authentication rule on a specific API endpoint. [1]
Cisco is an American multinational technology conglomerate based in San Jose, California, that develops networking and cybersecurity products. Security researchers at Field Effect and rapid7.com noted that the zero-day flaw exposes administrative functions to unauthorized remote users if left unpatched. [2][5][7]
In short
- Cisco issued a security advisory for CVE-2026-76504 on September 30, 2026.
- The vulnerability carries a CVSSv3.1 score of 9.8 and is caused by improper URL encoding handling.
- Unauthenticated remote attackers are actively exploiting the bug to bypass API authentication controls.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)Rapid7 Blog, 5d ago (the report this story comes from)
- [2]Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)rapid7.com, 5d ago
- [3]Critical Cisco Catalyst SD-WAN Zero-Day Under Active ExploitationInfosecurity Magazine, 5d ago
- [4]Cisco SD-WAN Manager hit by zero-day admin access attacknetworkworld.com, 5d ago
- [5]Cisco Catalyst SD-WAN Manager flaw exploitedField Effect, 5d ago
- [6]Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN ManagerThe Hacker News, 5d ago
Background
- [7]Cisco on Wikipedia
Our newsroom writes these reports with the help of software, from the 7 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Citrix issues patches for NetScaler memory overflow flaw under active attackBugs and Patches, 14h ago
- Citrix issues emergency updates for NetScaler zero day vulnerabilityTop Stories, 1d ago
- Hackers target Rejetto HFS servers following critical session forgery vulnerability discoveryTop Stories, 16h ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.