FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Cisco Catalyst SD-WAN Manager Authentication Bypass CVE-2026-76504

Cisco PSIRT has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (vManage) affecting multiple release branches. The flaw arises from improper handling of URL-encoded characters within the j_security_check API endpoint, allowing unauthenticated remote attackers to bypass security controls using crafted requests, such as POST /%6a_security_check. Active exploitation has been confirmed in the wild, prompting immediate inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants full administrative control over the SD-WAN control plane, enabling lateral movement and potential compromise of the entire managed network infrastructure. Immediate patching is required as no software workarounds are available.


LINK COPIED TO CLIPBOARD