CVE- 2026-76504 is a critical authentication bypass flaw in Cisco Catalyst SD-WAN Manager (formerly vManage) that lets an unauthenticated remote attacker reach the management API with administrator privileges. Cisco reports active exploitation in September 2026 and assigns a CVSS v3.1 score of 9.8. The U.S.
Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on 30 September 2026, with a remediation deadline of 3 October 2026 for federal agencies.
The vulnerability stems from improper handling of URI encoding in the API session-based authentication mechanism, classed as CWE-177 (Improper Handling of URL Encoding). Inconsistent decoding can allow a crafted HTTP request to bypass authentication on the protected endpoint, granting administrator-level access to the SD-WAN Manager’s management API regardless of credentials or user interaction.
Cisco notes that the flaw affects deployments irrespective of configuration and can expose operational data and management functions across the SD-WAN deployment. The advisory specifies the CVSS vector as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Cisco released fixes on 30 September 2026. First fixed releases are listed per affected branch, with guidance to migrate to supported, fixed releases. Providers of Cisco SD-WAN Cloud (Cisco Managed) can verify remediation status via the service interface. Detecting exploitation is supported by Cisco’s indicators and Snort rule 67179, and remediation requires upgrading all affected Managers and collecting admin-tech evidence for compromise assessment.