← RECON トップへ戻る ・ 記事一覧

CVE-2026-76504がCISA KEVに追加 — Cisco Catalyst SD-WAN ManagerのCVE-2026-76504

2026-09-30T00:00:00+09:00

CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-30付けで1件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。


CVE-2026-76504 — Cisco Catalyst SD-WAN Manager

脆弱性名: CVE-2026-76504

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.

This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

項目 内容
ベンダー/製品 Cisco / Catalyst SD-WAN Manager
対応期限(CISA) 2026-10-03
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-76504

※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。