CISA has added CVE-2026-76504, a critical authentication-bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Cisco says the issue can allow a remote unauthenticated attacker to access the affected system’s API with administrator privileges.
The vulnerability is associated with improper handling of URI encoding in an HTTP request. Cisco has published indicators and logging locations to help customers identify suspicious activity.
Hunting and remediation
- Upgrade affected Cisco Catalyst SD-WAN Manager deployments to a fixed release.
- Review service-proxy and vManage logs for unauthorized requests involving
j_security_checkand unusual source IPs. - Pay particular attention to anomalous usernames beginning with
viptela-reserved-. - Validate administrator accounts, API tokens and recent configuration changes after remediation.
CISA’s KEV listing is a high-priority signal: teams should act within their own risk and response procedures rather than waiting for their normal maintenance cycle.
Source: The Hacker News report; CISA KEV catalog.
