OverviewOn September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding (CWE-177).
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
About this summary. This is a short, independently written summary of an article first published by Rapid7. Cyber Security News did not report or verify the underlying story. Read the original: https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504
Source attribution: headline and facts are from Rapid7 (rapid7.com). Summary method: excerpt of the source description. See our source attribution policy.



