One hex-encoded letter walks past Cisco SD-WAN Manager's login, and it is already being used
2026-10-01Security
CVE-2026-76504 scores 9.8 and needs no credentials: encode a single character of the login path and the authentication rule stops matching, leaving the API open as the admin user. Cisco published the advisory on 30 September, said its PSIRT had already seen exploitation, and offered no workaround. CISA added it to the catalogue the same day.