Vulnerabilities

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.

Cisco vulnerability exploited

Cisco on Wednesday rolled out urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager that has been exploited in the wild.

Tracked as CVE-2026-76504 (CVSS score of 9.8), the flaw impacts the API session-based authentication mechanism and could allow remote, unauthenticated attackers to gain administrative access to a vulnerable system.

“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company warned.

According to Cisco, the issue resides in the improper handling of URI encoding in an HTTP request, allowing attacker requests to reach a restricted API endpoint.

“An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user,” Cisco explains.

All Catalyst SD-WAN Manager deployments are affected, regardless of their configuration, and there are no workarounds.

Advertisement. Scroll to continue reading.

CVE-2026-76504 was resolved in Catalyst SD-WAN versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Cisco-managed SD-WAN deployments have been patched as well.

Cisco has released indicators of compromise (IoCs) to help security teams hunt for potential exploitation attempts, and published general recommendations for hardening at-risk systems.

On Wednesday, the US cybersecurity agency CISA added the security defect to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days.

Neither Cisco nor CISA has shared details on the security bug’s in-the-wild exploitation.

“Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited Vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone – this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” WatchTowr head of threat intelligence Jake Knott said.

“None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target. Organizations running Catalyst SD-WAN Manager should upgrade to a fixed release immediately and follow vendor guidance, including hunting for POST requests to any URL-encoded variants of ‘/j_security_check’ and reviewing instances for signs exploitation has already occurred,” Knott added.

Related: Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Related Content

Vulnerabilities

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Mobile & Wireless

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.

Vulnerabilities

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Vulnerabilities

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

Email Security

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Vulnerabilities

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

Vulnerabilities

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.

Vulnerabilities

Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version