First published · Last updated
CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated remote attacker to access an affected system with admin privileges due to improper handling of URI encoding in an HTTP request. The advisory instructs applying vendor mitigations, following CISA BOD 26-04 guidance and forensics triage requirements, evaluating internet exposure, and discontinuing use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 1/10
- Global importance
- 4/10
- Impact magnitude
- 6/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Unpatched systems could permit unauthorized administrative access, so stakeholders must apply mitigations and follow CISA patching guidance.

