Critical Zero-Day Vulnerability in Cisco SD-WAN Manager
Successful exploitation of CVE-2026-76504 could allow a remote attacker to bypass authentication by sending a crafted HTTP request to the API of the affected system
Summary
Successful exploitation of CVE-2026-76504 could allow a remote attacker to bypass authentication by sending a crafted HTTP request to the API of the affected system
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-76504
Cisco has stated vulnerability CVE-2026-76504 has been exploited in the wild. The NHS England National CSOC assesses further exploitation as highly likely.
Edge devices like Cisco Catalyst SD-WAN are often internet-facing by design and are highly attractive targets to attackers, and there are an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers.
The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.
Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Introduction
Cisco has released a security advisory to address a critical zero-day vulnerability in SD-WAN Manager. Successful exploitation could allow an unauthenticated remote attacker to bypass authentication controls and gain administrator-level privileges to the affected system.
- CVE-2026-76504 - 'Improper Handling of URL Encoding' vulnerability - CVSSv3.1 Score: 9.8
Remediation advice
Affected organisations are encouraged to review the Cisco security advisory cisco-sa-sdwan-webauth-xr8beuuU and follow the steps below.
Remediation steps
| Type | Step |
|---|---|
| Action |
Perform a Comprehensive Compromise Assessment Organisations are strongly encouraged to follow the steps listed in the "Indicators of Compromise" section of Cisco's Advisory cisco-sa-sdwan-webauth-xr8beuuU Note: Organisations are strongly encouraged to complete this step first; or collect all relevant artifacts, including a snapshot of the device and all logs, to support threat hunting after patching. Patching before conducting the compromise assessment or collecting relevant artifacts may delete critical evidence. If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU |
| Patch |
Update to a Fixed Version Organisations are strongly encouraged to update Catalyst SD-WAN Manager. Organisations are strongly encouraged to use the Cisco Software Checker tool to determine the latest available version for their deployment. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU |
| Guidance |
Hardening Guidance for Cisco Catalyst SD-WAN Organisations are encouraged to follow Cisco's hardening guidance for Catalyst SD-WAN. https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide |
Definitive source of threat updates
Last edited: 30 September 2026 3:07 pm