CVE-2026-76504

● KEV CRITICAL

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of t...

Affects 0 products across 1 vendor.

CVSS 3.19.8
PatchUnknown
KEV Added2026-09-30
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-177: CWE-177
Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-177
CAPEC-72 URL Encoding
via CWE-177
CAPEC-120 Double Encoding
via CWE-177
CAPEC-468 Generic Cross-Browser Cross-Domain Theft
via CWE-177

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical severity vulnerability (CVE-2026-76504) affects the target system. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improp...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-76504?
A critical severity vulnerability (CVE-2026-76504) affects the target system. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improp...
What is the CVSS score for CVE-2026-76504?
CVE-2026-76504 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Is CVE-2026-76504 actively exploited?
Yes. CVE-2026-76504 is in the CISA KEV catalog (added 2026-09-30). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-76504?
Apply vendor patches for CVE-2026-76504. Monitor Cisco advisories.
What systems are affected by CVE-2026-76504?
CVE-2026-76504 affects: Cisco.
Vulnerability Details
CVE IDCVE-2026-76504
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-09-30
Last Modified2026-09-30
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Cisco — —
Cisco Catalyst Sd-Wan Manager 26.2 < 20.9.10.1 ≥ 20.12, < 20.12.8.2 ≥ 20.15, < 20.15.6.1 ≥ 20.18, < 20.18.4.1 ≥ 26.1, < 26.1.2.1
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 0 Days
CISA KEV● Active Exploitation Confirmed (added 2026-09-30)
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Cisco
CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2009-4912 10.0 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software be... CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6... CVE-2010-0581 10.0 Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12....
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-76504 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →