vulnerability
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
CriticalCVSS 10.0KEVEPSS 92%
Summary
A critical zero-day vulnerability (CVE-2026-76504) in Cisco SD-WAN Manager allows unauthenticated remote access to the API, potentially leading to compromise. Cisco has confirmed active exploitation of this flaw as of September 30, 2026. Customers using older versions of the SD-WAN Manager need to upgrade immediately, and those exposed to the internet should restrict access to the Manager through trusted hosts behind a firewall.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
