Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504)

Cisco has disclosed CVE-2026-76504, a critical authentication bypass in SD-WAN vManage disclosed as an exploited zero-day: any unauthenticated attacker can obtain a fully valid admin-level session with a single POST request. VulnCheck’s exploit development team reproduced the flaw, built detection artifacts, and currently finds about 1,500 internet-exposed vManage devices. There are no legitimate public exploits yet, though the researchers note at least one fake is circulating.

Source: www.vulncheck.com

Curated Permalink