← nejvýznamnější zprávy · všechny zprávy

KEV ✓ (3 z 3) EPSS 0.92 (nejvyšší)

Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

OverviewOn September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding (CWE-177). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user.According to…

Číst originál na Rapid7 →

CZ · EN/orig

Cisco US

tg: zneužíváno tg: zranitelnost tp: identita

CVE v události 3

CVEhodnoceníKEVEPSS
CVE-2026-20127 10.0 3.1 · cisco KEV ✓ 0.88
CVE-2026-20182 10.0 3.1 · cisco KEV ✓ 0.92
CVE-2026-76504 9.8 3.1 · cisco KEV ✓ –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.