Cisco SD-WAN Manager Zero-Day Allows Admin-Level API Access Without Credentials

Cisco has disclosed active exploitation of a critical zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that permits attackers to access administrative APIs without valid login credentials. The flaw enables unauthorized remote actors to gain full admin privileges over SD-WAN network infrastructure with no required workaround currently available. Cisco has released patched versions to address the vulnerability.
A critical vulnerability has been identified in Cisco's Catalyst SD-WAN Manager platform, a networking tool used to manage software-defined wide-area network deployments across organizations. The flaw allows remote attackers to bypass authentication mechanisms entirely, granting them the same access level that legitimate administrators possess. This represents a significant risk because SD-WAN infrastructure typically controls traffic routing and connectivity across distributed enterprise networks.
The vulnerability is particularly concerning because it has already been observed in active attacks in the wild, indicating that threat actors are actively exploiting the flaw. Cisco has responded by releasing updated software versions to remediate the issue, though organizations running vulnerable versions face exposure until patches are deployed.
Organizations relying on Catalyst SD-WAN Manager for network management could face substantial operational risk from this vulnerability. Compromised SD-WAN infrastructure may allow attackers to intercept, redirect, or disrupt network traffic, potentially affecting business continuity and data security across multiple locations. The absence of a temporary workaround may leave some organizations exposed during the patch deployment window, particularly those with complex networks requiring extensive testing before updates.