Cisco is urging companies to apply patches for a critical-severity vulnerability in its software used to configure and manage Cisco’s SD-WAN network. The flaw, an API authentication bypass, is being exploited.

The flaw exists in the API session-based authentication management of Cisco Catalyst SD-WAN Manager and stems from improper handling of URI encoding in HTTP requests, allowing an attacker to bypass an authentication rule designed to restrict access to a specific API endpoint.

The end result is that an unauthenticated and remote attacker could access impacted systems with admin privileges.

“An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system,” according to Cisco’s advisory on Wednesday. “A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.” 

The flaw (CVE-2026-76504) was found during a support case handled by Cisco’s customer support team.

Cisco said its PSIRT first “became aware of active exploitation” in September 2026, but did not give further details for that exploitation. The CVE was added to CISA’s Known Exploited Vulnerabilities catalog, where it’s listed as a Hex Encoding Vulnerability. The KEV catalog gives federal agencies a deadline of October 3, 2026, to apply patches for the flaw.

The flaw affects several versions of Cisco Catalyst SD-WAN Manager (regardless of system configuration). Below is a list of the software releases and corresponding fixes from Cisco.

Cisco's list of fixed releases

There are no workarounds for the flaw; however, Cisco said that On-Prem deployment customer environments should restrict access from unsecured networks to the impacted system.

“If access to the system is required from the internet, restrict system access to only known, trusted hosts on ports and protocols that are included in the user guides,” according to Cisco’s guidance. “Protect Cisco Catalyst SD-WAN Control Components behind a filtering device such as a firewall, and filter traffic to and from the system while allowing only known, trusted hosts to send traffic to the system.”