Skip to finding
§
High
Zero-click / edge
Confirmed
CVE-2026-76504

Attackers are using a URI-encoding bypass to enter Cisco Catalyst SD-WAN Manager as administrators.

Encoding one character prevents the API authentication rule from matching the endpoint path.

Affects

Cisco Catalyst SD-WAN Manager, the management and orchestration component for Cisco SD-WAN deployments.

What it enables

Unauthenticated API access with administrator privileges

An unauthenticated attacker reaches the Manager API.→↓The attacker sends a crafted HTTP request with an encoded character in the authentication endpoint path.→↓The authentication rule fails to match the encoded URI.→↓The API grants access with administrator privileges.
Why this matters

This is an actively exploited failure of the administrative boundary around an enterprise SD-WAN control plane.

Detail and 2 sources
Required access

Network reachability to the Cisco Catalyst SD-WAN Manager API; internet-exposed on-premises managers are directly reachable

Affected versions

Earlier than 20.9, 20.9 before 20.9.10.1, 20.12 before 20.12.8.2, 20.15 before 20.15.6.1, 20.18 before 20.18.4.1, 26.1 before 26.1.2.1, 26.2 before 26.2.1, Cisco SD-WAN Cloud before 20.15.605

Any unauthenticated caller who can reach the Manager API can attempt the bypass.

The crafted URI misses the authentication rule and receives administrator-level API access.

Cisco confirms active exploitation and has published fixed releases.

Evidence
Cisco PSIRT advisory confirms the authentication bypass, administrator access, affected releases, fixes, and active exploitation
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026