Cisco SD-WAN flaw gives attackers admin keys, and someone is already using it

CISA gave federal agencies three days to patch CVE-2026-76504 after evidence the authentication bypass is being exploited in the wild.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit enterprise network operations centre, rows of server racks with amber indicator lights, a single
Share

Key points

  • CISA added CVE-2026-76504, a critical flaw in Cisco's SD-WAN Manager, to its Known Exploited Vulnerabilities catalogue on 30 September 2026, with federal agencies told to patch by 3 October 2026.
  • The bug scores 9.8 out of 10 on the industry severity scale and lets an attacker on the internet log in as the top admin without a password.
  • The flaw sits in how the software reads web addresses, so a specially crafted request slips past the login check entirely.
  • CISA says there's evidence the flaw is already being used against real systems, though the agency hasn't named victims.
  • The three-day patch window is one of the tightest CISA has issued this year, matching the new Binding Operational Directive 26-04 rules for high-risk bugs.

Cisco's SD-WAN Manager is the control panel that large organisations use to run their wide-area networks: the plumbing connecting branch offices to data centres and cloud workloads. Own the Manager and you own the network. That's what makes CVE-2026-76504 ugly.

The US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalogue on 30 September. Federal civilian agencies had until 3 October to fix it. CISA only compresses a patch window that far when something is already being hit. We've now reported on three Cisco flaws at or above 9.8 in a single two-week stretch, and none of them had a workaround.

What does the bug actually do?

It lets a stranger on the internet become the admin. No password, no stolen session, no insider access required.

The technical cause is familiar. Cisco's software checks whether a web request is allowed to reach a protected part of its programming interface by reading the address of the request. That address can be written in hex encoding, where ordinary characters are replaced with their numeric codes. The authentication filter reads one version; the back-end processes a different one. Send a request that looks harmless to the filter but privileged to the back-end, and you walk straight in as the admin user.

It's the oldest failure mode in web security: two parts of the same system disagreeing on what a URL means.

Who is affected?

Anyone running Cisco's SD-WAN Manager with its web interface reachable from the internet, or from any network an attacker can reach. That covers a lot of enterprises and government networks. CISA's directive is binding only on federal civilian agencies, but the agency said all organisations should patch on the same timeline.

Fact Detail
CVE CVE-2026-76504
Product Cisco Catalyst SD-WAN Manager
Severity 9.8 / 10 (critical)
Added to KEV 30 September 2026
Federal patch deadline 3 October 2026
Attacker needs account? No

Should you worry?

If you're an ordinary customer of a company that uses Cisco SD-WAN, there's nothing for you to click or install. The risk is to the company's internal network. Watch for service disruptions or a breach notice from a provider in the coming weeks.

If you run the kit, the job is simpler and more urgent. Patch to the fixed Manager build, pull the admin interface off the public internet if it's still exposed, and review authentication logs for API calls that returned 200 OK against endpoints that should have required a session. The post-mortem will say, if you skip that log review, that the attacker was in before the patch landed. CISA's directive now expects that compromise check as part of remediation, not after it.

As The Hacker News noted in its write-up of the KEV addition, Cisco hasn't published exploitation details. That's normal. It doesn't buy time.

If the Manager is on the public internet today, assume someone has already knocked.

© 2026 Threat Vectr