CVE-2026-76504CISA KEVEPSS p74.6%
CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco / Catalyst SD-WAN Manager
Description
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.57% probability of exploitation · percentile 74.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-03 |
CISA KEV entry
Added to KEV: 2026-09-30