CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalogue on 30 September 2026. The vulnerability affects Cisco Catalyst SD-WAN Manager and is known as the Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability. It could allow an unauthenticated remote attacker to access an affected system with the privileges of the admin user.
The flaw results from improper handling of URI encoding in an HTTP request. It is an encoding vulnerability with a network-based attack vector and requires no authentication. The vulnerability carries a CVSS score of 9.8 and a Critical severity rating. The available data does not confirm whether a patch is available; patch status is listed as unknown.
CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available information does not identify use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must complete remediation by 3 October 2026.
CISA requires agencies to apply mitigations in accordance with Cisco’s instructions and comply with its BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Agencies must follow the applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and follow BOD 26-04 patching requirements. Although this requirement directly affects FCEB agencies, all organisations should review their exposure.
See the NVD entry and CISA KEV catalogue for full details.