Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4759 articles · 225307 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-76504KEVEXPLOITED
Cisco · Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability

Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Affected Products

VendorProductVersions
CiscoCisco Catalyst SD-WAN Manager18.3.6, 18.3.7, 18.3.8, 17.2.10, 18.3.6.1, 18.2.0, 18.4.3, 18.4.1, 17.2.8, 18.3.3.1, 18.4.0, 18.3.1, 17.2.6, 17.2.9, 18.3.4, 17.2.5, 18.3.1.1, 18.3.5, 18.4.0.1, 18.3.3, 17.2.7, 17.2.4, 18.3.0

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

Related News (5 articles)

Tier C
Rapid7 Blog1h ago
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
→ No new info (linked only)
Tier D
BleepingComputer2h ago
Cisco warns of new SD-WAN zero-day exploited in attacks
→ No new info (linked only)
Tier D
Heise Security2h ago
Jetzt patchen: Angreifer umgehen Anmeldung bei Cisco Catalyst SD-WAN Manager
→ No new info (linked only)
Tier C
VulDB3h ago
CVE-2026-76504 | Cisco Catalyst SD-WAN Manager up to 18.4.3 API Authentication authentication bypass
→ No new info (linked only)
Tier A
Cisco Security3h ago
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-177
PublishedSep 30, 2026
Last enriched3h ago
Trending Score126🔥
Source articles6
Independent6
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-76447
Cisco Identity Services Engine Certificate Reload Vulnerability
Trending: 10
MEDIUMCVE-2026-20121
CIsco FTD Bypass Access List
Trending: 10
MEDIUMCVE-2026-76427
Cisco ISE XML External Entity Injection Vulnerability
Trending: 8
MEDIUMCVE-2026-76426
Cisco ISE REST API SQL Injection Vulnerability
Trending: 8
MEDIUMCVE-2026-76431
Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 30, 2026
Added to CISA KEV
Sep 30, 2026
Discovered by ZDM
Sep 30, 2026
Actively Exploited
Sep 30, 2026