www.rapid7.com 30 Sept 2026, 15:09 UTC

Cisco SD-WAN Flaw Exploited to Grant Attackers Admin Access

CyberSIXT Evidence Panel Source marked as original reporting

RAPID 7 reports that Cisco Catalyst SD-WAN Manager is being exploited in the wild for CVE-2026-76504, a critical API authentication bypass affecting the SD-WAN Manager. The flaw stems from improper handling of URL encoding (CWE-177), enabling an unauthenticated, remote attacker to send a crafted HTTP request that bypasses authentication on a specific API endpoint and gain admin-level access. Cisco’s advisory states a CVSSv3.1 score of 9.8, and exploitation has been observed since September 2026.

The vulnerability affects systems with ports exposed to the internet, and there is no workaround; vendor fixes are available and organisations are urged to upgrade immediately to a fixed release. Rapid7 advises emergency remediation outside normal patch cycles and to search internet-facing systems for signs of compromise.

Updates and mitigation from Cisco outline the fixed software releases by release family, including first fixed versions such as 20.9.10[.]1 for 20.9, 20.12.8[.]2 for 20.12, 20.15.6[.]1 for 20.15, 20.18.4[.]1 for 20.18, 26.1.2[.]1 for 26.1, and 26.2.1 for 26.2. Cloud-hosted Cisco SD-WAN Cloud (Managed) is already addressed in release 20.15.605; on-premises mitigation is to apply the updates listed and to restrict internet access to trusted hosts or behind filtering devices if exposure is required.

Given that exploitation has occurred, Rapid7 emphasises auditing affected systems for compromise and engaging Cisco TAC with a CVE-2026-76504 title for assistance. Additional context notes prior, unauthenticated peering authentication flaws earlier in 2026 (CVE-2026-20127 and CVE-2026-20182), underscoring the importance of urgent remediation across internet-facing SD-WAN components.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline