ZeroDayAlert

CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Cisco Catalyst SD-WAN Manager Added to KEV 2026-09-30 Federal due 2026-10-03 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Cisco Catalyst SD-WAN Manager is affected by this vulnerability. The flaw permits unauthenticated remote access to the system with admin privileges through improper handling of URI encoding in HTTP requests. The record does not specify which versions are vulnerable, the scope of deployments most at risk, or whether cloud-hosted and on-premises instances are both affected.

How to check whether this touches you

  • Inventory: do you operate Cisco Catalyst SD-WAN Manager in your environment, either as an appliance or cloud service?
  • Reachability: is the management interface reachable from the internet or from untrusted networks without VPN or IP allowlisting?
  • Version check: retrieve the running version from the system administration console or API; version identification alone is a signal only, as backported fixes may exist in patches that do not increment the minor version.
  • Log inspection: search authentication logs for admin user sessions originating from unexpected source IPs or without corresponding login events, especially in the weeks before you became aware of this issue.

What to do

  1. Immediately restrict network access to the Catalyst SD-WAN Manager interface to trusted administrative networks only, using firewall rules, VPN enforcement, or IP allowlisting.
  2. Check Cisco's security advisories and release notes for the patched version applicable to your running release; apply the patch according to your maintenance window if one is available.
  3. If a patch is unavailable for your version, evaluate whether discontinuation of the product or migration to an alternative is feasible within your compliance deadline (federal remediation due date is 2026-10-03).
  4. Enable and retain authentication and access logs at the highest verbosity available; ensure logs cover at least 90 days of history.
  5. If internet-facing, notify your CISO and incident response team; escalate to your organisation's vulnerability management or security operations centre for prioritisation.

If you find you were exposed

Exploitation of unauthenticated admin access typically occurs before public disclosure, so you should search authentication logs and system audit trails backwards from the present date for admin sessions without a corresponding login event or with suspicious timestamps. Log retention is your primary constraint; if logs have been rotated or deleted, conduct a file-system forensic review of the Catalyst SD-WAN Manager appliance to check for evidence of unauthorised configuration changes or data exfiltration. Document all findings for regulatory reporting if required.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-76504 is being exploited. It cannot tell you whether Catalyst SD-WAN Manager is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →