MikhbarMIKHBAR
Cybersecurity

Cisco Patches Actively Exploited SD-WAN Zero-Day Flaw

Cisco has rolled out urgent security software updates to address a critical authentication bypass vulnerability in Catalyst SD-WAN Manager that is currently being exploited in active attacks.

Cisco Patches Actively Exploited SD-WAN Zero-Day Flaw

Critical Zero-Day Flaw in Catalyst SD-WAN Manager

Cisco has rolled out urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager that has been actively exploited in the wild. Tracked as CVE-2026-76504 with a CVSS score of 9.8, the severe flaw impacts the API session-based authentication mechanism and allows remote, unauthenticated attackers to gain administrative access to vulnerable enterprise systems. Further details are available from SecurityWeek in the original source material.

The company was alerted to active in-the-wild exploitation by the Cisco PSIRT in September 2026. The vulnerability stems from the improper handling of URI encoding within HTTP requests, which permits malicious attacker requests to reach a restricted API endpoint without proper validation.

Technical Details and Attack Vector

According to Cisco's security advisory, an attacker can exploit this security defect by sending a specifically crafted HTTP request to the API of an affected system. A successful exploit allows the adversary to bypass authentication entirely and gain access to the system's API as an administrative user.

The vendor explicitly noted that all Catalyst SD-WAN Manager deployments are affected by this vulnerability regardless of their specific configuration, and administrators should note that there are currently no available workarounds to mitigate the risk without applying updates.

Software Updates and Remediation Steps

To address CVE-2026-76504, Cisco has resolved the issue in Catalyst SD-WAN versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Additionally, Cisco-managed SD-WAN deployments have already been patched by the company.

For self-hosted and enterprise environments, Cisco strongly recommends that customers upgrade to a fixed software release immediately. Furthermore, the networking giant has released indicators of compromise to help corporate security teams hunt for potential exploitation attempts and published general recommendations for hardening at-risk systems.

CISA KEV Catalog Addition and Industry Response

Following the disclosure and patch release, the US cybersecurity agency CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply the necessary patches within a three-day window.

Neither Cisco nor CISA has publicly shared detailed technical intelligence regarding the exact nature of the in-the-wild exploitation campaigns targeting the zero-day bug. However, security experts have emphasized the platform's high attractiveness to malicious actors due to its centralized management architecture.

Analyst Insights on SD-WAN Security

Industry experts have highlighted a recurring trend involving vulnerabilities found within enterprise networking infrastructure platforms. Jake Knott, head of threat intelligence at WatchTowr, pointed out that Cisco SD-WAN has repeatedly appeared on security catalogs throughout the year, signaling that malicious actors recognize the strategic value of the platform.

Because enterprises rely heavily on the platform as a centralized management tool to configure and monitor large corporate networks, it remains a prime target. Organizations running Catalyst SD-WAN Manager have been advised to review their server instances carefully for signs of prior exploitation and follow comprehensive vendor guidance.

Sources

  • SecurityWeekCisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Continue chronologically