Cisco Patches Actively Exploited Critical Zero-Day in SD-WAN Manager

Fifth SD-WAN zero-day exploited in the wild in 2026; customers urged to upgrade immediately

By LineZotpaper
Published
Read Time2 min
Cisco has released security updates to address a critical zero-day vulnerability in its Catalyst SD-WAN Manager, tracked as CVE-2026-76504, which is being actively exploited in attacks to gain admin privileges remotely.

Cisco warned customers on Wednesday that attackers are actively exploiting a critical zero-day vulnerability in the Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. The vulnerability, tracked as CVE-2026-76504, affects all deployments regardless of configuration and allows unauthenticated attackers to access affected systems remotely with admin privileges.

The flaw lies in API session-based authentication management, specifically improper handling of URI encoding in HTTP requests. According to Cisco, an attacker can bypass an authentication rule intended to restrict access to a particular API endpoint by sending a crafted HTTP request containing the URI-encoded character "%6a" (representing "j").

Cisco did not elaborate on the attacks but provided indicators of compromise. It advised administrators investigating potentially compromised systems to check the "serviceproxy-access.log" file (located at /var/log/nms/containers/service-proxy) and the "vmanage-server.log" file (at /var/log/nms/) for entries related to "j_security_check" from unknown or unauthorized IP addresses.

"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company said in a security advisory. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."

Fixed releases are available for versions 20.9, 20.12, 20.15, 20.18, 26.1, and 26.2, with specific patch versions listed in the advisory. Customers running earlier releases are advised to migrate to a fixed release.

CVE-2026-76504 is the fifth SD-WAN zero-day actively exploited in the wild since the start of 2026. In February, Cisco patched a critical information disclosure flaw (CVE-2026-20127) in SD-WAN Manager that had been exploited since at least 2023. Another maximum-severity authentication bypass flaw in the Catalyst SD-WAN Controller was also tagged as actively exploited earlier this year.

§

Analysis

Why This Matters

  • Enterprise networks using Cisco SD-WAN Manager are at risk of full compromise if the vulnerability is exploited. Attackers gaining admin privileges can monitor, redirect, or disrupt traffic across up to 6,000 managed devices.
  • The frequency of SD-WAN zero-days in 2026 (this is the fifth) suggests a systemic security challenge in the product line, putting pressure on organizations to accelerate patching and consider compensating controls.
  • Immediate action is required: checking logs for signs of compromise and upgrading to fixed releases. Delayed patching leaves networks exposed to ongoing attacks.

Background

Cisco Catalyst SD-WAN Manager is network management software that enables administrators to monitor and manage up to 6,000 SD-WAN devices from a single dashboard. It is a central control point in many enterprise and service provider networks. The vulnerability CVE-2026-76504 is an authentication bypass in the management API, caused by improper URI encoding handling. Cisco PSIRT became aware of active exploitation in September 2026 and released patches on September 30.

Key Perspectives

[Cisco Systems]: The company has publicly warned customers, released patches for all supported versions, and provided detailed indicators of compromise (IOCs) and log analysis steps. It urges immediate patching and offers TAC assistance for compromised systems. [Threat Actors]: The attackers are actively exploiting the zero-day using URI-encoded characters (%6a) to bypass authentication. They appear to be targeting SD-WAN Manager deployments indiscriminately to gain privileged access. [Security Community]: The repeated exploitation of SD-WAN zero-days (five in 2026) raises concerns about the overall security posture of the platform. Researchers and incident responders are likely analyzing the IOC data to determine if the attacks are part of a broader campaign or multiple independent threat groups.

What to Watch

  • Whether additional security advisories or fixes are released for other SD-WAN components (Controller, Edge devices) as investigations continue.
  • Reports of widespread compromises or data breaches linked to this vulnerability.
  • Adoption rate of the patches among enterprise customers, as slow patching could lead to increased exploitation.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.