Executive Summary
Facts Only
* CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities (KEV) catalog.
* The vulnerability is in Cisco Catalyst SD-WAN Manager session authentication.
* The CVSS score for the vulnerability is 9.8.
* A remote attacker can access the system with administrator-level privileges without credentials.
* The cause is improper handling of URI encoding in an HTTP request, bypassing an authentication rule.
* Cisco's Product Security Incident Response Team learned about active exploitation in September 2026.
* Cisco's Technical Assistance Center (TAC) discovered the issue during a customer support investigation.
* No workaround for the vulnerability is currently available.
* For on-premises deployments, restrict internet access and place SD-WAN control components behind a firewall from trusted hosts.
* Affected versions include those earlier than 20.9, 20.9, 20.12, 20.15, 20.18, 26.1, and 26.2.
* Cisco recommends upgrading to fixed software releases.
Full Take
From the original · Security Affairs (Pierluigi Paganini)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.Read the full story at securityaffairs.com
