CISCO has released urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager, which has been exploited in the wild. The flaw, tracked as CVE-2026-76504 with a CVSS score of 9.8, targets the API session-based authentication mechanism. It stems from improper handling of URI encoding in an HTTP request, enabling remote, unauthenticated attackers to reach a restricted API endpoint and bypass authentication to gain administrative access.
Cisco confirms that all Catalyst SD-WAN Manager deployments are affected, regardless of configuration, and notes there are no workarounds. The company began warning in September 2026 and has published patched software releases to remediate the issue. The fixed releases are Catalyst SD-WAN versions 26.2.1, 26.1.2[.]1, 20.18.4[.]1, 20.15.6[.]1, 20.12.8[.]2, and 20.9.10[.]1; Cisco-managed SD-WAN deployments have also been updated.
Cisco has provided indicators of compromise to assist security teams in hunting for exploitation attempts and has issued general recommendations for hardening at-risk systems.
CISA has added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch within three days. While Cisco and CISA have not disclosed in‑the‑wild details, industry commenters emphasise the importance of upgrading immediately and monitoring for POST requests to URL-encoded variants of “/j_security_check” as part of investigation efforts.