← DOOMRADAR
cyber · First tracked by DoomRadar:
68DOOM SCORE

Critical Cisco SD-WAN flaw is under active exploitation

Cisco says attackers are exploiting CVE-2026-76504, a critical authentication-bypass flaw in Catalyst SD-WAN Manager. The vulnerability can grant unauthenticated remote attackers administrator-level access, and CISA has urged covered organizations to apply fixes.

By DoomRadar · Published on DoomRadar . Updated .

Event date: Cisco issued its security warning and fixed-release recommendation on September 30, 2026. [1][2]

What happened

Cisco identified CVE-2026-76504 in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. Cisco classified it as critical, with a CVSS severity score of 9.8, and recommended upgrading to a fixed software release. [1]

References for this detail (1)

The flaw involves improper handling of URI encoding in an HTTP request. An attacker can send a specially crafted request to the SD-WAN Manager API and bypass an authentication rule intended to restrict access to a specific endpoint. [2][3]

References for this detail (2)

Cisco said the vulnerability is already under active exploitation. If an exposed system is compromised, the access level described in the reporting could enable data loss, system downtime or complete system takeover. [1]

References for this detail (1)

The reported exposure concerns the manager component used to administer SD-WAN environments, rather than a general claim that every Cisco networking device is vulnerable. Cisco said mitigation had already been deployed to its Catalyst SD-WAN Cloud Hosted environments. [1]

References for this detail (1)

Context from the sources

The vulnerability is an authentication bypass: the attack does not require the attacker to authenticate before attempting the crafted request, according to the technical description published by ISMG. [2][3]

Explore the sources and reporting timeline

3 source links · 3 domains

These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.

1 of these links repeat a headline already present, allowing for punctuation and publisher branding. Repeated wording is not additional confirmation.

Source timeline

Oldest to newest among the available source dates, not a chronology of the incident. Article publication dates come from the source; other recorded dates may reflect when a link was found.

  1. Article published: Oct 1, 2026, 2:17 PM UTC[1] Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitationinfosecurity-magazine.comReferenced for: detail 1, detail 3, detail 4
  2. Recorded source date: Oct 1, 2026, 9:46 PM UTC[3] Breach Roundup: Cisco SD-WAN Flaw Under Attackgovinfosecurity.comReferenced for: detail 2, detail 5
  3. Recorded source date: Oct 2, 2026, 1:16 AM UTC[2] Breach Roundup: Cisco SD-WAN Flaw Under Attackbankinfosecurity.comReferenced for: detail 2, detail 5

Questions answered by the reporting

What does the vulnerability allow?

A specially crafted request can bypass an authentication rule and provide an unauthenticated remote attacker with administrator privileges on an affected SD-WAN Manager. [2][3]

What this could mean for you

Digital services

An affected organization's network-management system could be taken over or disrupted.

The authentication bypass may give an unauthenticated remote attacker administrator-level access to SD-WAN Manager.

Reported basis: [1][2] · The possible effect is interpretation.

Depends on: The organization must be running an affected deployment that remains exploitable.

Work & business

Organizations could experience network-management downtime or loss of access to systems they administer.

Cisco described possible consequences including system downtime and complete system takeover after exploitation.

Reported basis: [1] · The possible effect is interpretation.

Depends on: An attacker must successfully exploit an affected and unremediated system.

Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.

For your country

Choose a country to check how this event could affect you.

What changes the outlook

Risk increases if…

Further exploitation of unpatched, reachable SD-WAN Manager deployments.

Evidence that attackers have obtained administrator access in affected organizations.

Pressure eases if…

Deployment of Cisco's fixed software release or the stated mitigation.

Removal of vulnerable systems from attacker access until remediation is complete.

Still unclear

The reporting does not identify the attackers, affected organizations or the number of compromised systems.

The affected software versions and the full scope of exploitation are not specified in the excerpts.

Market implications

Market impact

Loading market analysis...
Sources (3)

References for the reported details. Separate links do not necessarily mean independent confirmation.

[1] Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation ↗infosecurity-magazine.com · Article published: Oct 1, 2026, 2:17 PM UTC
Available excerpt
Cisco has issued an urgent security update to address a newly uncovered zero-day vulnerability in Cisco Catalyst SD-WAN Manager which has already been exploited in…
A short excerpt from our source record; open the original for the full article.
[2] Breach Roundup: Cisco SD-WAN Flaw Under Attack ↗bankinfosecurity.com · Recorded source date: Oct 2, 2026, 1:16 AM UTC
Available excerpt
Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week: Cisco SD-WAN under attack, OpenAI agents attempted to hack a Canadian…
A short excerpt from our source record; open the original for the full article.
[3] Breach Roundup: Cisco SD-WAN Flaw Under Attack ↗govinfosecurity.com · Recorded source date: Oct 1, 2026, 9:46 PM UTC
Available excerpt
Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week: Cisco SD-WAN under attack, OpenAI agents attempted to hack a Canadian…
A short excerpt from our source record; open the original for the full article.

AI-assisted analysis · . Based on linked headlines and available excerpts. Methodology · Report an error.