Cisco patches actively exploited zero-day in Catalyst SD-WAN Manager
Cisco has released fixes for a critical zero-day, CVE-2026-76504, in its Catalyst SD-WAN Manager software that attackers are already exploiting to gain unauthenticated admin access. The flaw stems from improper URI encoding handling that lets crafted HTTP requests bypass authentication on a specific API endpoint. Cisco says it learned of active exploitation in September 2026 and is urging customers to upgrade immediately.