CRITICAL: Cisco Catalyst SD-WAN Manager Auth Bypass Exploited in the Wild
Cisco confirmed active exploitation of CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager that grants unauthenticated attackers admin API access. CISA added it to KEV with an October 3 deadline. No workaround exists, so upgrade to the fixed release and hunt the logs for encoded j_security_check requests.