KEV ✓ (3 z 3) EPSS 0.92 (nejvyšší)
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
OverviewOn September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding (CWE-177). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user.According to…
Cisco US
CVE v události 3
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-20127 | 10.0 3.1 · cisco | KEV ✓ | 0.88 |
| CVE-2026-20182 | 10.0 3.1 · cisco | KEV ✓ | 0.92 |
| CVE-2026-76504 | 9.8 3.1 · cisco | KEV ✓ | – |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.