Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Executive Summary

Cisco has issued an advisory on September 30 that attackers are exploiting a zero‑day flaw (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager. The vulnerability allows unauthenticated remote users to use the Manager’s API with admin privileges, bypassing authentication. Cisco has released patches; no workaround exists.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-30T15:24:54+00:00 - Category: threat-intel

Original Description: Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a

"Some people thrive on huge, dramatic change. Some people prefer the slow and steady route. Do what's right for you."

— Julie Morgenstern
Source: The Hacker News