Skip to content
cve — cve-2026-76504

grep -rl "CVE-2026-76504" ./articles

CVE-2026-76504

CVE-2026-76504 scores 9.8 and needs no credentials: encode a single character of the login path and the authentication rule stops matching, leaving the API open as the admin user. Cisco published the advisory on 30 September, said its PSIRT had already seen exploitation, and offered no workaround. CISA added it to the catalogue the same day.

1 article — 2026-10-01

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered