# Cisco patches actively exploited SD-WAN authentication bypass

_Published Wednesday, September 30, 2026 at 2:25 PM EDT · Security · Latest · Tier 1 — Major_

![Cisco patches actively exploited SD-WAN authentication bypass — Primary](https://www.bleepstatic.com/content/hl-images/2025/03/04/Cisco_headpic.jpg)

Cisco released fixes for CVE-2026-76504, a critical flaw in Catalyst SD-WAN Manager that the company says attackers are actively exploiting. The vulnerability lets unauthenticated attackers gain remote administrator access and affects all deployments regardless of configuration.

A crafted HTTP request can exploit improper handling of encoded characters to bypass an authentication rule protecting an API endpoint. The software lets administrators manage up to 6,000 SD-WAN devices from one dashboard. Cisco recommends upgrading to a fixed release and checking logs for suspicious requests involving j_security_check; it did not disclose further details of the attacks.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/N3L7SRurrwWf4G8-nH8uIh
Published: 2026-09-30T18:25:03.728Z
Story chronology: 2026-09-30T14:46:40.000Z
Retrieved: 2026-09-30T20:29:54.820Z
Publisher: Tech & Business (techandbusiness.org)
