Cisco Catalyst SD-WAN Manager authentication bypass (CVE-2026-76504) exploited in the wild
Tags Policy & Law

A CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-76504, is being actively exploited and was added to CISA's Known Exploited Vulnerabilities catalog on October 1, 2026. The flaw stems from improper handling of URI encoding in an HTTP request, letting an unauthenticated attacker bypass an authentication rule and gain administrative access to the SD-WAN controller. CISA gave federal civilian agencies until October 3 to apply fixes. Cisco published fixed releases and indicators of compromise, and the UK's NCSC and NHS England both issued alerts calling further exploitation highly likely.
Technical significance
Administrative control of an SD-WAN controller exposes every tunnel, policy and site it manages, so a no-credentials, no-interaction bypass is a network-wide risk rather than a single-host compromise. The three-day federal remediation window and parallel UK alerts indicate defenders should treat this as a same-week patch.