Cisco has released a critical security update to address a zero-day vulnerability in its Catalyst SD-WAN Manager, which is currently being exploited in the wild. This vulnerability, identified as CVE-2026-76504, involves a flaw in the API session-based authentication management. It allows remote attackers to gain administrative privileges on affected systems without requiring authentication. With a CVSS score of 9.8, this issue is classified as critical, highlighting the potential for significant damage such as data loss, system downtime, or even total system compromise if left unaddressed.
Any Cisco Catalyst SD-WAN Manager systems with internet-exposed ports are at risk. Cisco strongly advises customers to upgrade to a fixed software release as there are no workarounds available to address this vulnerability. The flaw arises from improper handling of URI encoding in HTTP requests, which can be exploited to bypass authentication and grant attackers administrative access. This access could lead to the unauthorized user gaining control over the network, allowing them to modify or delete critical files and backups.
Cisco has already deployed mitigation measures in its cloud-hosted environments for the Catalyst SD-WAN. However, it emphasizes that customers should assess these measures for effectiveness in their specific environments. Rapid7, a cybersecurity firm, also urges organizations using the affected systems to upgrade immediately and audit their systems for any signs of compromise. The US Cybersecurity Infrastructure and Security Agency has added this vulnerability to its known exploited vulnerabilities catalog, further emphasizing the need for prompt action.
In recent months, Cisco has reported similar security concerns, including a maximum severity flaw in its Identity Services Engine. Organizations must remain vigilant and act swiftly to protect their systems from such vulnerabilities.

