Cisco patches an authentication zero-day in Catalyst SD-WAN Manager already exploited in the wild
CVE-2026-76504 lets an unauthenticated attacker bypass Catalyst SD-WAN Manager authentication through URI encoding and gain admin rights. There is no workaround: patch immediately and inspect j_security_check logs.