EN
İhbar gönder

Exploited Cisco SD-WAN flaw grants admin access without credentials, fifth zero-day this year

Cisco has patched a critical, actively exploited flaw in Catalyst SD-WAN Manager that grants administrative access without credentials. ☀ CVE-2026-76504 scores 9.8; all deployments are affected and there is no workaround. ☀ Attackers bypass authentication with a URL-encoding trick; one console can manage up to 6,000 devices. ☀ CISA ordered US federal agencies to fix the flaw by 3 October; the attackers have not been identified.

Cisco genel merkezi, San Jose
ARCHIVEImage: Cisco headquarters (Building 10), San Jose, California. Photo: Ashwin Kumar, Wikimedia Commons, CC BY-SA 2.0, 12 July 2017. Archive image.

Cisco on 30 September patched a critical vulnerability that attackers are actively exploiting in Catalyst SD-WAN Manager, the software organisations use to run their wide area networks from a single console. Tracked as CVE-2026-76504, the flaw carries a severity score of 9.8 out of 10 and allows a remote, unauthenticated attacker to gain administrative access. Cisco said it became aware of exploitation in September during a technical support case.

The flaw stems from improper handling of URL encoding in the software’s API session authentication. Attackers send crafted HTTP requests that encode the letter ‘j’ as %6a to bypass an authentication rule. Cisco says all SD-WAN Manager deployments are affected regardless of configuration and there is no workaround. Because a single SD-WAN Manager can manage up to 6,000 devices, compromising it can mean control over an entire network.

The flaw is fixed in versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1, and Cisco-managed deployments have been patched. Customers on releases earlier than 20.9 need to migrate to a supported version. Cisco advises restricting internet access to management consoles and reviewing logs for ‘j_security_check’ activity from unknown IP addresses.

The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalogue and ordered federal civilian agencies to fix it by 3 October 2026 and assess whether their systems were compromised. Neither Cisco nor CISA has said who is behind the attacks or how many organisations were targeted.

VERIFICATION STATUSLAST UPDATED 13:17
VERIFIED

The CVE, 9.8 score, affected and fixed versions and CISA's 3 October deadline were confirmed through Help Net Security, SecurityWeek, BleepingComputer, Aviatrix and News4Hackers, citing Cisco and CISA advisories.

UNCERTAIN

BleepingComputer counts this as the fifth exploited SD-WAN zero-day of 2026, while WatchTowr says eight Cisco SD-WAN CVEs were added to CISA's catalogue this year; the figures may rest on different definitions.

MISSING

The attackers' identity and the number of organisations targeted have not been disclosed.

Some stories are prepared with AI assistance; every story is reviewed and labelled by a person before publication. Real photographs are published with their source and licence; AI-generated images carry the ILLUSTRATIVE label.

Leave a comment

No account needed. Your email address is not published. Comments are reviewed before they appear.