CVE-2026-76504
Cisco Catalyst SD-WAN Manager API authentication bypass allows unauthenticated admin access (CVE-2026-76504)
Cisco Catalyst SD-WAN Manager has an API authentication bypass (CVE-2026-76504, CVSS 9.8) that can give an unauthenticated remote attacker admin API access. Cisco PSIRT reports active exploitation; patch and restrict exposure.
What happened
The Cisco Catalyst SD-WAN Manager API mishandles URI encoding in HTTP requests. A crafted request can bypass an authentication rule intended to restrict access to a specific API endpoint. An unauthenticated remote attacker can exploit this to reach the API with the privileges of the admin user. The CVSS vector rates the impact high for confidentiality, integrity and availability (CVSS 3.1, 9.8).
Cisco PSIRT states that, in September 2026, it became aware of active exploitation of this vulnerability. There are no workarounds that address the flaw itself; Cisco's guidance is to upgrade to a fixed software release and, for on-premises deployments, to restrict network access to the system.
Who is affected
The affected product is Cisco Catalyst SD-WAN Manager. The releases listed in Cisco's advisory are 17.2.10, 18.2.0, 18.3.6, 18.3.6.1, 18.3.7, 18.3.8, 18.4.1 and 18.4.3. On-premises deployments are the primary concern; Cisco states that for Cloud Hosted environments the access-restriction mitigation is already deployed. Organisations that expose the management API or management interface to untrusted networks should treat this as urgent.
What to do now
- Upgrade to the fixed software release. Cisco states a fix is available and strongly recommends upgrading. Confirm the fixed release for your installed version in the Cisco PSIRT advisory.
- Until the upgrade is complete, apply Cisco's mitigation for on-premises deployments: restrict access from unsecured networks such as the internet, place Catalyst SD-WAN control components behind a filtering device or firewall, and allow only known, trusted hosts to send traffic to the system on required ports and protocols. Cisco notes this mitigation is already deployed for Cloud Hosted environments.
- Review API session activity and access controls for evidence of unauthorised admin access, particularly if the system has been reachable from the internet.
How to detect it
Monitor API session and authentication logs for admin-level access from internet-facing addresses that are not in your explicit trusted-host rules. Because this vulnerability grants admin API access without credentials, any unexpected new admin session or privileged API action on an on-premises deployment is worth investigating.
Beyond the patch
An unauthenticated route to admin API access is an exposure-management problem first: if the management plane is not reachable from the internet, the practical risk drops sharply. Virtual CISO Services can help you map and reduce that exposed management-plane footprint. Because Cisco PSIRT reports active exploitation and no user interaction is required, Managed Detection & Response is the right safety net for detecting and investigating post-exploitation activity while you patch.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Catalyst SD-WAN Manager | 18.3.6 18.3.7 18.3.8 17.2.10 18.3.6.1 18.2.0 18.4.3 18.4.1 | No fixed version listed yet |