Cisco says attackers are actively exploiting a newly disclosed zero-day vulnerability in its Catalyst SD-WAN Manager, tracked as CVE-2026-76504. The flaw affects remote access to the Manager’s API and can allow an attacker to act with administrative privileges, according to Cisco’s advisories cited by multiple outlets.

The vulnerability is described as an authentication bypass tied to how the Manager handles URI encoding in API requests. Reporting across sources states that a remote attacker who can reach the Manager API, without needing credentials or a prior login session, can use the API as the admin user. The advisory also indicates there is no workaround, and organizations must upgrade to fixed releases.

Outlets differ mainly in emphasis and surrounding detail. One outlet focuses on the broader warning and Cisco’s security update release, while others highlight the specific mechanism (URI-encoding/authentication bypass), the reachable-internet exposure risk, and the list of fixed software versions per release train. Several sources also note Cisco provides limited details on exploitation scope, the attacker’s identity, and whether patching removes already-existing access, and it urges customers to follow logging and mitigation guidance while upgrading.