Cisco SD-WAN Manager authentication bypass is under active exploitation
Cisco says attackers are exploiting CVE-2026-76504, a critical unauthenticated API authentication bypass in Cisco Catalyst SD-WAN Manager that can grant admin-level access. Rapid7 reports that vendor updates are available, there is no workaround, and recommends emergency patching and checking affected systems for compromise.
Why it matters For operators of internet-facing SD-WAN Manager systems, patching alone is not a complete response: reported exploitation also warrants checking whether attackers already gained access.
What to watch next Rapid7 expects vulnerability checks in its October 1 content release; the source does not confirm their delivery.
Rapid7 ↗