Cisco warns of active exploitation of CVSS 9.8 SD-WAN Manager auth bypass
Cisco has warned of active exploitation of CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager. Hex-encoding a character in the URI bypasses the j_security_check rule and grants admin API access without credentials; no workarounds exist, only patching.
- CVE-2026-76504: auth bypass in Cisco Catalyst SD-WAN Manager, CVSS 9.8
- Hex-encoded URI character bypasses the j_security_check authentication rule
- Cisco confirmed active exploitation; no workarounds, patch is the only fix
- Attackers can alter fabric config, reroute traffic and move laterally
Read next
Security