Network Security Engineer: 2026-09-30
7 minutes in total
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
Cisco, 2026-09-30. Read, 7 min.
Cisco disclosed CVE-2026-76504 (CVSS 9.8), a flaw in the API authentication of Cisco Catalyst SD-WAN Manager that could let an unauthenticated, remote attacker access an affected system with the privileges of the admin user, and says its PSIRT became aware of active exploitation in September 2026. Fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, and the Cisco-managed cloud release 20.15.605 needs no customer action.
Why it matters for this role: Until the upgrade lands, keep SD-WAN Manager behind a filter that admits only known, trusted hosts, because Cisco has no workaround for on-premises systems beyond that mitigation.
Sign in to take it.