High severity Vulnerability

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Overview

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Cisco Catalyst SD-WAN Manager is under active exploitation. Report it as CVE-2026-76504, patch by 2026-10-03. Imported automatically from CISA Known Exploited Vulnerabilities on Sep 30, 2026.

Indicators of Compromise

Signals that suggest this is present on a system.

  • CVE-2026-76504

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used