## Overview
CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) list on September 30, 2026. This vulnerability affects Cisco Catalyst SD-WAN Manager. It enables unauthenticated remote attackers to gain admin access through improper URI encoding handling in HTTP requests.
## Technical Details
The vulnerability arises from flaws in the API session-based authentication management. Attackers can exploit this by sending crafted HTTP requests that bypass authentication rules. This allows them to access restricted API endpoints as if they were legitimate admin users. The CVSS score of 9.8 indicates a high severity level, underscoring the urgency for remediation.
## Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive system functions. Attackers could manipulate or extract data, posing significant risks to network security and operational integrity. The potential for widespread exploitation makes this a critical issue for organizations using Cisco Catalyst SD-WAN Manager.
## Mitigation
Defenders should immediately apply available patches from Cisco to remediate this vulnerability. Organizations must review their network configurations and monitor for any unusual API access patterns. Regular audits and updates to security protocols are essential to protect against such threats.
CSURFACE Threat Sensor