Cisco’s Catalyst SD-WAN Manager is affected by CVE-2026-76504, a critical API authentication-bypass vulnerability that Cisco says has been exploited in the wild. Rapid7 reports that the flaw has a CVSS v3.1 score of 9.8 and can allow an unauthenticated remote attacker to reach a specific API endpoint with administrator privileges through a crafted request.

The immediate priority is to identify every affected SD-WAN Manager deployment, especially internet-facing systems, and move to Cisco’s fixed release without waiting for a normal patch cycle. Rapid7 says Cisco has not provided a workaround, although access restrictions can reduce exposure while updates are applied. Cloud-managed customers should confirm their service status with Cisco rather than assume they are covered.

Because exploitation has been reported, remediation should include targeted compromise assessment. Rapid7 highlights Cisco-recommended log review for unusual requests associated with the affected authentication path and usernames. Teams should compare potential indicators with their normal operational baseline, preserve evidence, and escalate suspicious findings through incident response. CISA added the issue to its Known Exploited Vulnerabilities catalog with an October 3 remediation due date for federal civilian agencies.

Source: Rapid7: Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild.

By Allan