Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
Cisco warns of new SD-WAN zero-day exploited in attacks
- September 30, 2026
- 10:46 AM

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
The CVE-2026-76504 vulnerability affects all deployments regardless of system configuration, was found in API session-based authentication management, and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
"This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint," Cisco added.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system."
While the company didn't share further details regarding attacks exploiting CVE-2026-76504, it shared indicators of compromise (IOCs) warning admins that threat actors are using %6a as the URI-encoded character "j" in malicious requests.
It also advised security teams investigating potentially compromised SD-WAN systems to check the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/for entries related to j_security_check from unknown or unauthorized IP addresses.
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," it added, advising admins first to collect admin-tech files to support the review.
| Cisco Catalyst SD-WAN Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Fifth actively exploited SD-WAN zero-day in 2026
CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the start of the year.
Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February, exploited since at least 2023, and tagged a maximum-severity Catalyst SD-WAN Controller auth bypass flaw (CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.
More recently, in early June, Cisco warned of two more SD-WAN zero-days (CVE-2026-20245 and CVE-2026-20262) that attackers exploited to gain root privileges on vulnerable systems.
Since November 2021, the Cybersecurity and Infrastructure Security Agency (CISA) has tagged 90 Cisco vulnerabilities as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seatOriginally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.