CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation observed in the wild. The flaw, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to bypass authentication by sending a crafted HTTP request to the API, gaining admin-level access. Organizations are urged to apply patches immediately and review specific log files for signs of compromise, including suspicious POST requests to URL-encoded variants of '/j_security_check' and activity involving user accounts starting with 'viptela-reserved-'.
AI-extracted · verify before operational use