Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager
Authentication bypass vulnerability allows privilege escalation to admin level

Key Takeaways
- Cisco has confirmed active exploitation of CVE-2026-76504 in the wild.
- The zero-day affects Catalyst SD-WAN Manager and allows authentication bypass.
- Attackers can escalate to admin privileges, risking full infrastructure compromise.
- Patches are available; immediate update is recommended for all affected deployments.
- Organizations should monitor Cisco advisories for additional details and verification.
Related Security News

Cisco Advises Urgent Patching of Critical Authentication Bypass in SD-WAN Manager
Cisco has confirmed that a critical vulnerability in Catalyst SD-WAN Manager is being actively exploited. The flaw, tracked as CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and Cisco states there is no workaround. The advisory was published on September 30, 2026.




