Cisco patches actively exploited zero-day in Catalyst SD-WAN Manager
Cisco has released fixes for a critical zero-day, CVE-2026-76504, in its Catalyst SD-WAN Manager software that attackers are already exploiting to gain unauthenticated admin access. The flaw stems from improper URI encoding handling that lets crafted HTTP requests bypass authentication on a specific API endpoint. Cisco says it learned of active exploitation in September 2026 and is urging customers to upgrade immediately.
GoKawiil's interpretation of the reporting above, not reported fact.
Because Catalyst SD-WAN Manager can control up to 6,000 network devices from one dashboard, a successful exploit could give attackers sweeping access across an organization's network infrastructure. Cisco's release of indicators of compromise and log-checking guidance suggests the company expects many customers may already be compromised and need to investigate rather than just patch. The case underscores the recurring risk of authentication-bypass flaws in centralized network management tools.
- CVE-2026-76504 allows unauthenticated attackers to gain admin privileges on Cisco Catalyst SD-WAN Manager.
- Cisco confirmed active exploitation in September 2026 and released patches, urging immediate upgrades.
- Admins are advised to check specific log files for signs of compromise and can contact Cisco TAC for help.
Source: bleepingcomputer.com, 2026-09-30
Published there as: “Cisco warns of new SD-WAN zero-day exploited in attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.