CVE-2026-76504: Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
- Vendor
- Cisco
- Product
- Catalyst SD-WAN Manager
- Vulnerability
- Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- Date added
- Sep 30, 2026
- CISA due date (U.S. federal agencies)
- Oct 3, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-177
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02