Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Summary

Cisco has issued a warning about attackers actively exploiting a critical authentication bypass vulnerability in their Catalyst SD-WAN Manager. This flaw, identified as CVE-2026-76504, allows remote attackers without any login credentials to gain administrative access via the Manager's API. Cisco has released fixed versions of the software, and no workaround is currently available.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to gain administrative control over critical network management systems, posing a significant risk to organizational security.

Severity

9.8 Critical

Defender Context

This advisory highlights a critical vulnerability in a widely used network management system, emphasizing the need for prompt patching and robust API security monitoring. Defenders should prioritize updating Cisco Catalyst SD-WAN Manager to the latest fixed releases and ensure their network segmentation and access controls are tightly managed to mitigate the risk of unauthorized API access.

Read Full Story →