Cisco Catalyst SD-WAN Manager has an unauthenticated admin-API bypass, and there is no workaround.
What happened
Advisory cisco-sa-sdwan-webauth-xr8beuuU covers CVE-2026-76504. A crafted HTTP request can get past the API session check because URI encoding is handled badly. The caller reaches the admin API without authenticating. Cisco rates it CVSS 9.8. Cisco says there are no workarounds.
The original brief also recorded a CISA Known Exploited Vulnerabilities due date of 3 October 2026. Patching does not answer whether the API was already used.
Who is affected
- Cisco Catalyst SD-WAN Manager, regardless of configuration
- Releases earlier than 20.9 must move to a fixed release
- Cisco-managed SD-WAN Cloud release 20.15.605 is already addressed. No user action is required there
What to do now
- Upgrade to a fixed train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1.
- If the manager is reachable, check logs for unexpected admin API access. Cisco's indicator example is a URI-encoded character in the request, not only the sample %6a.
Source: Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU
Also on the blog
- FortiMail zero-day is exploited, and most fixes are not shipped
- CISA lists two Zammad bugs that an AI-driven attack already chained to root
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.