CiberLATAMbywhalemate

Cisco fixes CVE-2026-76504 in SD-WAN Manager

Cisco fixed CVE-2026-76504 in Catalyst SD-WAN Manager, an actively exploited authentication bypass with no workaround.

Whalemate Labs · AI-assisted researchPublished:2 min read

Cisco fixed CVE-2026-76504 in Catalyst SD-WAN Manager, a critical flaw with a CVSS score of 9.8 that let an unauthenticated remote attacker reach admin privileges through a manipulated HTTP request. Reports said there was no workaround, CISA added it to its KEV catalog, and Cisco released version 26.2.1.

Cisco has released a fix for CVE-2026-76504 in Catalyst SD-WAN Manager, a critical flaw rated CVSS 9.8 that let an unauthenticated remote attacker bypass API session-based authentication and gain administrator privileges. Multiple outlets reported active exploitation, and CISA added the issue to its KEV catalog the same day.

What does CVE-2026-76504 allow?

The vulnerability lets an attacker bypass an authentication rule with a manipulated HTTP request by abusing incorrect URI encoding handling. According to the CVE record, the impact is remote access with the privileges of the administrator user on the affected system.

The Stack reported that Cisco identified the issue as CVE-2026-76504 and said there are no workarounds to mitigate it. In that same report, the company said the fixed release is 26.2.1.

Heise described the problem as a URL encoding bug that allows an attacker to skip login and obtain remote administrative access. The Hacker News, meanwhile, said attackers were exploiting the flaw to use the Catalyst SD-WAN Manager API as an administrator, without credentials.

What did Cisco and security outlets say?

The reports agree that Cisco responded with security updates and that the vulnerability was already being actively exploited. BleepingComputer also said CISA added CVE-2026-76504 to its KEV catalog on the same day as the advisory.

Cisco also pointed to two detection paths in logs, /var/log/nms/serviceproxy-access.log and /var/log/nms/vmanage-server.log, according to Heise. That gives defenders a concrete way to review activity tied to the incident.

WatchTowr said in an independent analysis that access gained through the API carries the same privileges as the built-in administrative account, which by default can perform any operation supported by the system. That point was presented as a third-party technical interpretation, not as an official Cisco statement.

What is known about the timeline?

The public timeline remains limited. An analysis by PK Sharma says Cisco's advisory only dates the attacks to September 2026, without specifying the first day or how long exploitation lasted.

That does not change the core facts of the case: this is a critical vulnerability, actively exploited, with no workaround and a patch now available. The sources reviewed do not provide a regional angle specific to Latin America at this time.

Sources

View all