chiprook
← Security
SecuritySeptember 30, 2026, 21:39

Cisco warns of active exploitation of CVSS 9.8 SD-WAN Manager auth bypass

Cisco has warned of active exploitation of CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager. Hex-encoding a character in the URI bypasses the j_security_check rule and grants admin API access without credentials; no workarounds exist, only patching.

Cisco warns of active exploitation of CVSS 9.8 SD-WAN Manager auth bypass
#Cisco
Read next
Security

Cisco FMC authentication bypass CVE-2026-20079 has CVSS 10.0

Security

Three Artifactory flaws under active exploitation allow auth bypass and admin access

Security

Active exploitation attempts target WSO2 API Manager JWT bypass

Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws