Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager Enables Remote Admin Access

Cisco disclosed a critical zero‑day authentication bypass (CVE‑2026‑76504) in its Catalyst SD‑WAN Manager that allows unauthenticated attackers to act as the admin user via the API. The flaw affects all supported versions and has no workaround, prompting immediate patching. For compliance teams, the issue underscores the need for continuous privileged‑access monitoring and evidence of timely patch management.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
thehackernews.com

Critical Authentication Bypass (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager

What It Is — Cisco disclosed a critical zero‑day authentication bypass (CVE‑2026‑76504) in its Catalyst SD‑WAN Manager. The flaw allows a remote attacker with no valid credentials to invoke the manager’s API as the built‑in admin user. No workaround exists; fixed releases are available.

Exploitability — The vulnerability is actively being exploited in the wild. It is a remote, unauthenticated attack with a CVSS v3.1 base score of 9.8 (Critical).

Affected Products — Cisco Catalyst SD‑WAN Manager (all supported on‑prem and virtual editions prior to the September 2026 patch).

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of privileged‑access activity is essential; an unauthenticated admin bypass defeats static access lists and creates audit gaps.
  • Demonstrable, timely patch management provides the evidence auditors demand for a defensible control posture.
  • Enterprise buyers now require proof that critical authentication controls are both enforced and verifiable in real time.

Recommended Actions

  • Deploy the September 2026 security patch for Cisco Catalyst SD‑WAN Manager immediately.
  • Verify the running version across all SD‑WAN sites and confirm the patch is applied.
  • Review and tighten API authentication mechanisms (e.g., enforce MFA, restrict IP ranges).
  • Enable detailed logging of all API calls and integrate them with a SIEM for continuous monitoring.
  • Conduct a post‑patch audit to capture evidence of remediation for compliance reporting.

Source: The Hacker News – Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD‑WAN Manager

📰 Original Source
https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →