PULSE
FEED
ransomn0n reclama a Houston Thyroid & Endocrine Specialists · US · Healthcareransomeclipse reclama a The Japan Times · JP · Otherransomvexy ransomware reclama a Summit Electric Supply · US · Energy & Utilitiesransomsafepay reclama a wolfusofsky.de · DE · Not Foundransomkairos reclama a Le Centre National de l'Expertise Hospitalière (CNEH) · FR · Healthcareransomplay reclama a Titus · DE · Technologyransomplay reclama a Airtech Mechanical Services · US · Professional Servicesransomplay reclama a Orth Automobile · DE · Manufacturingransominterlock reclama a Blaise C. Bender, PC · US · Professional Servicesransomaurora reclama a Buford-Thompson Company, LTD · US · Manufacturingransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomn0n reclama a Houston Thyroid & Endocrine Specialists · US · Healthcareransomeclipse reclama a The Japan Times · JP · Otherransomvexy ransomware reclama a Summit Electric Supply · US · Energy & Utilitiesransomsafepay reclama a wolfusofsky.de · DE · Not Foundransomkairos reclama a Le Centre National de l'Expertise Hospitalière (CNEH) · FR · Healthcareransomplay reclama a Titus · DE · Technologyransomplay reclama a Airtech Mechanical Services · US · Professional Servicesransomplay reclama a Orth Automobile · DE · Manufacturingransominterlock reclama a Blaise C. Bender, PC · US · Professional Servicesransomaurora reclama a Buford-Thompson Company, LTD · US · Manufacturingransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Other
← Todos los CVEs
CVE Watch30 sept 2026

CVE-2026-76504

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

CVSS

9.8

Crítico

EPSS

—

KEV

SÍ

30 sept 2026

Exploit Today

50

0-100

Publicado: 30 sept 2026 · Última mod.: 30 sept 2026 · CWE-177

EPSS · 30d

Sin historial EPSS suficiente todavía.

Ficha del catálogo KEV

Producto

Cisco / Catalyst SD-WAN Manager

Vulnerabilidad

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Añadido a KEV

30 sept 2026

Remediar antes de

3 oct 2026

Uso conocido en ransomware

No

Descripción resumida

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Acción requerida

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Notas

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76504

Descripción técnica

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-967486.5 MED
15.7%
——5PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.6d
CVE-2026-761727.5 ALT
12.7%
——4fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.29d
CVE-2026-674486.5 MED
11.4%
——3Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to return true. A malicious website can request /%61pi/events, skip corsOriginAccessControl(), reach the /api/events WebSocket handler, and receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets from an unauthenticated default Mailpit instance after the user visits the site. This is a regression of the earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. This issue is fixed in version 1.30.6.12d
CVE-2026-153718.1 ALT
28.2%
——8Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.33d
CVE-2026-590839.1 CRÍ
28.5%
——9Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.79d
CVE-2026-410419.1 CRÍ
46.5%
——14URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.79d