Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4862 articles · 225328 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-76504KEVEXPLOITED
Cisco · Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability

Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Affected Products

VendorProductVersions
CiscoCisco Catalyst SD-WAN Manager18.3.6, 18.3.7, 18.3.8, 17.2.10, 18.3.6.1, 18.2.0, 18.4.3, 18.4.1, 17.2.8, 18.3.3.1, 18.4.0, 18.3.1, 17.2.6, 17.2.9, 18.3.4, 17.2.5, 18.3.1.1, 18.3.5, 18.4.0.1, 18.3.3, 17.2.7, 17.2.4, 18.3.0

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

Related News (6 articles)

Tier D
The Hacker News2h ago
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
→ No new info (linked only)
Tier C
Rapid7 Blog2h ago
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
→ No new info (linked only)
Tier D
BleepingComputer3h ago
Cisco warns of new SD-WAN zero-day exploited in attacks
→ No new info (linked only)
Tier D
Heise Security3h ago
Jetzt patchen: Angreifer umgehen Anmeldung bei Cisco Catalyst SD-WAN Manager
→ No new info (linked only)
Tier C
VulDB4h ago
CVE-2026-76504 | Cisco Catalyst SD-WAN Manager up to 18.4.3 API Authentication authentication bypass
→ No new info (linked only)
Tier A
Cisco Security4h ago
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-177
PublishedSep 30, 2026
Last enriched4h ago
Trending Score128🔥
Source articles7
Independent7
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-76447
Cisco Identity Services Engine Certificate Reload Vulnerability
Trending: 10
MEDIUMCVE-2026-20121
CIsco FTD Bypass Access List
Trending: 10
MEDIUMCVE-2026-76427
Cisco ISE XML External Entity Injection Vulnerability
Trending: 8
MEDIUMCVE-2026-76426
Cisco ISE REST API SQL Injection Vulnerability
Trending: 8
MEDIUMCVE-2026-76431
Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 30, 2026
Added to CISA KEV
Sep 30, 2026
Discovered by ZDM
Sep 30, 2026
Actively Exploited
Sep 30, 2026