Cisco urges all users of Cisco Catalyst SD-WAN Manager to upgrade to the fixed releases immediately. Because no workaround exists, upgrading to the patched version is the only recommended mitigation. Users should monitor Cisco advisories for specific version numbers and release notes.
Quick answers
What is CVE-2026-76504?
Cisco urges all users of Cisco Catalyst SD-WAN Manager to upgrade to the fixed releases immediately. Because no workaround exists, upgrading to the patched version is the only recommended mitigation. Users should monitor Cisco advisories for specific version numbers and release notes.
How severe is CVE-2026-76504?
critical
Is CVE-2026-76504 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-76504 be mitigated?
Cisco urges all users of Cisco Catalyst SD-WAN Manager to upgrade to the fixed releases immediately. Because no workaround exists, upgrading to the patched version is the only recommended mitigation. Users should monitor Cisco advisories for specific version numbers and release notes.
CVSS
—
Vendor
Cisco
Published
Oct 1, 2026 · 03:51
Patch
Unknown / not confirmed
Affected products
Catalyst SD-WAN Manager
Mitigation
Cisco urges all users of Cisco Catalyst SD-WAN Manager to upgrade to the fixed releases immediately. Because no workaround exists, upgrading to the patched version is the only recommended mitigation. Users should monitor Cisco advisories for specific version numbers and release notes.
Cisco has released security updates to address CVE-2026-76504, a critical zero-day vulnerability in Catalyst SD-WAN Manager that is being actively exploited in the wild. The flaw allows authentication bypass and privilege escalation to admin privileges, potentially enabling full compromise of SD-WAN infrastructure.
Cisco has confirmed that a critical vulnerability in Catalyst SD-WAN Manager is being actively exploited. The flaw, tracked as CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and Cisco states there is no workaround. The advisory was published on September 30, 2026.