www.infosecurity-magazine.com 1 Oct 2026, 14:30 UTC

Cisco SD-WAN Zero Day Exposes Internet Facing Systems to Attackers

CyberSIXT Evidence Panel

CISCO has released an urgent security update for Cisco Catalyst SD-WAN Manager after the discovery of a zero-day vulnerability that is already being exploited in the wild. The flaw, tracked as CVE-2026-76504, affects the API session-based authentication management and could permit an unauthenticated, remote attacker to access the system with administrator privileges.

The CVSS score is 9.8, classed as critical, and Cisco warns that any Catalyst SD-WAN Manager systems with internet-facing ports are potentially at risk of compromise.

Exploitation stems from improper handling of URI encoding in an HTTP request, which can allow an unauthorised user to bypass authentication and gain access to the API as an administrator. Once inside, an attacker could pivot throughout the network, alter or delete files and backups, and potentially take control of the affected environment. Cisco notes that a mitigation has already been deployed for SD-WAN Cloud Hosted environments and that there are no workarounds other than applying the security update.

Citations from Rapid7 urge immediate upgrade to a fixed release and recommend auditing affected systems for compromise. The US CISA has added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog and urges organisations to apply mitigations, in line with other recent advisories from Cisco regarding active exploitation of related flaws such as CVE-2026-76460 affecting Cisco ISE.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline