Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.

Cisco vulnerability exploited

Cisco on Wednesday rolled out urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager that has been exploited in the wild.

Tracked as CVE-2026-76504 (CVSS score of 9.8), the flaw impacts the API session-based authentication mechanism and could allow remote, unauthenticated attackers to gain administrative access to a vulnerable system.

“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company warned.

According to Cisco, the issue resides in the improper handling of URI encoding in an HTTP request, allowing attacker requests to reach a restricted API endpoint.

“An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user,” Cisco explains.

All Catalyst SD-WAN Manager deployments are affected, regardless of their configuration, and there are no workarounds.

Advertisement. Scroll to continue reading.

CVE-2026-76504 was resolved in Catalyst SD-WAN versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Cisco-managed SD-WAN deployments have been patched as well.

Cisco has released indicators of compromise (IoCs) to help security teams hunt for potential exploitation attempts, and published general recommendations for hardening at-risk systems.

On Wednesday, the US cybersecurity agency CISA added the security defect to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days.

Neither Cisco nor CISA has shared details on the security bug’s in-the-wild exploitation.

“Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited Vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone – this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” WatchTowr head of threat intelligence Jake Knott said.

“None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target. Organizations running Catalyst SD-WAN Manager should upgrade to a fixed release immediately and follow vendor guidance, including hunting for POST requests to any URL-encoded variants of ‘/j_security_check’ and reviewing instances for signs exploitation has already occurred,” Knott added.

Related: Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

David Cass has joined Grayscale Investments as Chief Risk Officer.

Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.

Alex Stamos has become Chief Information Security Officer at Cognition.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.