CVE-2026-76504CISA KEVEPSS p74.6%

CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco / Catalyst SD-WAN Manager

Description

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.57% probability of exploitation · percentile 74.6% · 2026-10-05T12:00:23Z
Last modified2026-10-03

CISA KEV entry

Added to KEV: 2026-09-30

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.