CVE-2026-76504

CRITICAL CISA KEV POC TTE Zero-Day Pub 30/09 Upd 01/10

Overview

This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.

Vulnerability Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Impact

An unauthenticated remote attacker can exploit this vulnerability to gain administrative access to the affected system's API without any user interaction or valid credentials. This enables full control over the system, including the ability to view, modify, or delete configuration data, potentially leading to complete system compromise and disruption of network management operations.

Solution

Cisco has released a security advisory (cisco-sa-sdwan-webauth-xr8beuuU) addressing this issue for Cisco Catalyst SD-WAN Manager. Administrators should apply the patches provided in the advisory promptly. Detailed patch instructions and version-specific updates are available on Cisco’s official security center website to mitigate this authentication bypass vulnerability.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (6)

Vendor Product Version CPE
cisco Cisco Catalyst Sd-Wan Manager All cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cisco Cisco Catalyst Sd-Wan Manager All cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cisco Cisco Catalyst Sd-Wan Manager All cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cisco Cisco Catalyst Sd-Wan Manager All cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cisco Cisco Catalyst Sd-Wan Manager All cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cisco Cisco Catalyst Sd-Wan Manager 26.2 cpe:2.3:a:cisco:catalyst_sd-wan_manager:26.2:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (1)

Repository Author Stars Forks Date Link
ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept
EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)
ShadowForge-Cyber 0 0 2026-09-30 View
Exploited in Wild CONFIRMED
Ransomware IN USE
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

7 events
2026-10-01
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-01
Exploited by akira

Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AnyDesk, Bloodhound, Cloudflared (1613 known victims)

2026-09-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-30
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-09-30
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: Cisco, product: Catalyst SD-WAN Manager

2026-09-30
PoC Published (1 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Detected as Exploited in the Wild (356 sightings)

Active exploitation confirmed with 356 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Insecure Direct Object Reference
91% idor
Authentication Bypass
88% auth_bypass
Privilege Escalation
64% privilege_escalation
Authorization Bypass
49% authz_bypass

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-120 Double Encoding
30%
Low Medium
CAPEC-468 Generic Cross-Browser Cross-Domain Theft
30%
— Medium
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
30%
High High
CAPEC-72 URL Encoding
30%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-76504
sec.cloudapps.cisco.com
GitHub CVE
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504