{"id":244710,"date":"2026-10-01T01:29:38","date_gmt":"2026-10-01T06:29:38","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/10\/cisco-warns-of-attackers-exploiting-critical-authentication-bypass-in-sd-wan-manager"},"modified":"2026-10-01T01:29:38","modified_gmt":"2026-10-01T06:29:38","slug":"cisco-warns-of-attackers-exploiting-critical-authentication-bypass-in-sd-wan-manager","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/10\/cisco-warns-of-attackers-exploiting-critical-authentication-bypass-in-sd-wan-manager","title":{"rendered":"Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/cisco-warns-of-attackers-exploiting-critical-authentication-bypass-in-sd-wan-manager.webp\"><\/a><\/p>\n<p>Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-webauth-xr8beuuU\" target=\"_blank\">advisory<\/a> on September 30.<\/p>\n<p>The flaw, <strong>CVE-2026\u201376504<\/strong>, could allow a remote attacker with no login access to use the Manager\u2019s API as the admin user. Fixed releases are available, and there is no workaround. It carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager\u2019s API that handles login sessions.<\/p>\n<p>The Manager mishandles URI encoding in an HTTP request. A crafted request can therefore bypass an authentication rule intended to restrict access to a single API endpoint.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026\u201376504, could allow a remote attacker with no login access to use the Manager\u2019s API as the admin user. Fixed releases are [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-244710","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244710"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244710\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}