Cisco Patches Actively Exploited Catalyst SD-WAN Zero-Day Allowing Admin Access
Cisco has released security updates for a critical zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2026-76504. Attackers are actively exploiting the flaw to gain administrative privileges on vulnerable systems.
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that allows administrators to monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
Cisco urges customers to install the fixed releases
“In September 2026, Cisco PSIRT became aware of active exploitation of this vulnerability,” Cisco warned on Wednesday. “Cisco strongly recommends that you upgrade to a fixed software release that fixes this vulnerability.”
CVE-2026-76504 affects all deployments regardless of system configuration. The vulnerability exists in API session-based authentication management and allows an unauthenticated, remote attacker to access a vulnerable system with administrative privileges.
“This vulnerability is due to improper handling of URI encoding in HTTP requests, which allows requests to bypass authentication rules intended to restrict access to specific API endpoints,” Cisco said.
“An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system’s API.”
Indicators of compromise for CVE-2026-76504
Cisco did not provide details about the attacks exploiting CVE-2026-76504. However, the company shared an indicator of compromise showing that threat actors are using %6a, the URI-encoded character for “j,” in malicious requests.
Security teams investigating potentially compromised SD-WAN systems should review the Service proxy access.log file under /var/log/nms/containers/service proxy and the vmanage-server.log file under /var/log/nms/ for entries related to j_security_check from unknown or unauthorized IP addresses.
Customers can open a case with Cisco TAC to determine whether Catalyst SD-WAN Manager has been compromised. Cisco advises administrators to first collect administrative technical files for review.
Cisco Catalyst SD-WAN versions affected and fixed releases
| Cisco Catalyst SD-WAN release | First fixed release |
|---|---|
| Before 20.9 | Move to a fixed release. |
| 20.9 | 20.9.10.1 |
| December 20th | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Fifth actively exploited SD-WAN zero-day reported in 2026
CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability to be actively exploited in the wild since the beginning of 2026.
In February, Cisco patched an information disclosure vulnerability in SD-WAN Manager, tracked as CVE-2026-20127, which had been exploited since at least 2023.
In May, Cisco patched a maximum-severity Catalyst SD-WAN Controller authentication bypass vulnerability, tracked as CVE-2026-20182. The flaw was actively exploited in zero-day attacks to gain administrative privileges on unpatched devices.
More recently, in early June, Cisco warned of two additional SD-WAN zero-days, CVE-2026-20245 and CVE-2026-20262. Attackers exploited the vulnerabilities to gain root privileges on vulnerable systems.
Since November 2021, the Cybersecurity and Infrastructure Security Agency (CISA) has added 90 Cisco vulnerabilities to its Known Exploited Vulnerabilities catalog. Four of those vulnerabilities affected Cisco Catalyst SD-WAN Manager, while seven were exploited in ransomware operations.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



