CISCO PATCHES CRITICAL SD-WAN ZERO-DAY EXPLOITED IN ATTACKS

Cisco released emergency security updates on September 30, 2026, for a critical authentication-bypass vulnerability that attackers are actively exploiting against Catalyst SD-WAN Manager systems.

Tracked as CVE-2026-76504, the vulnerability carries a CVSS severity score of 9.8 out of 10. It allows an unauthenticated remote attacker to bypass an API authentication rule and gain the privileges of an administrator. Cisco says there are no workarounds that fully address the flaw. sec.cloudapps.cisco.com

HOW THE VULNERABILITY WORKS

CVE-2026-76504 is caused by improper handling of URI encoding in an HTTP request. An attacker can send a specially crafted request to a vulnerable system’s API, bypass authentication and access the interface as an administrative user.

The vulnerability affects Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage, regardless of system configuration. The product provides centralized monitoring and management for SD-WAN infrastructure, making administrator-level compromise especially serious.

Cisco discovered the vulnerability while resolving a Technical Assistance Center support case. Its Product Security Incident Response Team subsequently confirmed that the flaw was being actively exploited in September 2026.

Cisco has not attributed the attacks to a particular threat actor or disclosed how many organizations were compromised. Those details remain unknown; the active exploitation and technical impact are confirmed by Cisco.

INTERNET-EXPOSED SYSTEMS FACE THE GREATEST RISK

Cisco specifically warns that internet-accessible Catalyst SD-WAN Manager systems are at risk. Successful exploitation could give an attacker extensive control over the management environment, potentially exposing configuration data and enabling changes to centrally administered network infrastructure.

On-premises customers should immediately restrict access from unsecured networks and permit connections only from known, trusted hosts. Cisco describes those controls as temporary mitigations rather than substitutes for installing a fixed release.

Cisco-managed cloud environments already have the recommended network-access mitigation in place, and Cisco has fixed its cloud service in release 20.15.605. No customer action is required for that hosted release.

Leave a Comment

Your email address will not be published. Required fields are marked *