CVE-2026-76504 is an authentication-bypass vulnerability in API session-based authentication management in Cisco Catalyst SD-WAN Manager. Improper handling of URI encoding in HTTP requests enables a crafted request to bypass an authentication rule intended to protect a specific API endpoint. A remote unauthenticated attacker can thereby access the API with administrator-user privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical, unauthenticated authentication-bypass vulnerability in Cisco Catalyst SD-WAN Manager's API. Improper URI encoding handling enables a crafted HTTP request to bypass an authentication restriction and access an API endpoint as the administrator-level user. Cisco reports active exploitation.
A critical, CVSS 9.8 remote API authentication-bypass flaw in Cisco Catalyst SD-WAN Manager caused by improper URL-encoding handling (CWE-177). It permits unauthenticated attackers to bypass an API authentication rule and access the API as an administrator.
A critical CVSS 9.8 authentication-logic flaw in Cisco Catalyst SD-WAN Manager. Improper URL encoding validation can enable an unauthenticated remote attacker to gain administrator privileges and remotely control devices through the integrated API.
Vulnerabilità critica di bypass dell'autenticazione in Cisco Catalyst SD-WAN Manager. Una gestione impropria dell'URI encoding nelle richieste HTTP permette a un attaccante remoto non autenticato di aggirare la regola di autenticazione di un endpoint API e ottenere privilegi amministrativi.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.