thehackernews.com 30 Sept 2026, 15:24 UTC

Cisco Warns of Active Exploitation in Critical SD-WAN Flaw

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISCO says attackers are exploiting a critical authentication bypass in the Cisco Catalyst SD-WAN Manager, potentially allowing remote unauthenticated access via the Manager’s API. The flaw is tracked as CVE-2026-76504 and scores 9.8 out of 10 on CVSS. It stems from improper URI encoding in an HTTP request, which can bypass an authentication rule guarding a single API endpoint. An attacker would need no credentials, only the ability to send a crafted request to the Manager’s API. Cisco warns that Managers exposed to the internet are at risk, and by default the admin user holds the netadmin role with full device permissions.

Cisco states active exploitation was observed in September 2026, identified while its TAC supported a customer case. The advisory does not disclose how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access. The vulnerability affects the SD-WAN Manager across configurations; there is no workaround, only fixed releases. The first fixed releases are provided for each release train (e.g., 20.9.10[.]1 for 20.9, 20.12.8[.]2 for 20.12, up to 26.x trains).

Cloud-managed SD-WAN Cloud is already fixed in 20.15.605 and requires no action. Cisco also recommends limiting exposure of on‑premise managers to unsecured networks, using a jump host or management subnet for any necessary internet access, and reviewing for signs of compromise via j_security_check entries in specified log files. For suspected compromises, Cisco asks customers to open a Severity 3 TAC case and include CVE-2026-76504 in the title. The U.S. CISA Known Exploited Vulnerabilities list had eight Cisco SD-WAN flaws catalogued in 2026.

View full article

Article by CyberSIXT