Skip to main content

Critical Zero-Day Vulnerability in Cisco SD-WAN Manager

Successful exploitation of CVE-2026-76504 could allow a remote attacker to bypass authentication by sending a crafted HTTP request to the API of the affected system

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-76504 could allow a remote attacker to bypass authentication by sending a crafted HTTP request to the API of the affected system


Threat details

Exploitation of CVE-2026-76504

Cisco has stated vulnerability CVE-2026-76504 has been exploited in the wild. The NHS England National CSOC assesses further exploitation as highly likely.

Edge devices like Cisco Catalyst SD-WAN are often internet-facing by design and are highly attractive targets to attackers, and there are an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers.

The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.

Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.


Introduction

Cisco has released a security advisory to address a critical zero-day vulnerability in SD-WAN Manager. Successful exploitation could allow an unauthenticated remote attacker to bypass authentication controls and gain administrator-level privileges to the affected system.

  • CVE-2026-76504 - 'Improper Handling of URL Encoding' vulnerability - CVSSv3.1 Score: 9.8

Remediation advice

Affected organisations are encouraged to review the Cisco security advisory cisco-sa-sdwan-webauth-xr8beuuU and follow the steps below.


Remediation steps

Type Step
Action

Perform a Comprehensive Compromise Assessment

Organisations are strongly encouraged to follow the steps listed in the "Indicators of Compromise" section of Cisco's Advisory cisco-sa-sdwan-webauth-xr8beuuU

Note: Organisations are strongly encouraged to complete this step first; or collect all relevant artifacts, including a snapshot of the device and all logs, to support threat hunting after patching. Patching before conducting the compromise assessment or collecting relevant artifacts may delete critical evidence.

If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. 


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
Patch

Update to a Fixed Version

Organisations are strongly encouraged to update Catalyst SD-WAN Manager.

Organisations are strongly encouraged to use the Cisco Software Checker tool to determine the latest available version for their deployment.


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
Guidance

Hardening Guidance for Cisco Catalyst SD-WAN

Organisations are encouraged to follow Cisco's hardening guidance for Catalyst SD-WAN.


https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide


Last edited: 30 September 2026 3:07 pm