MikhbarMIKHBAR
Cybersecurity

Cisco Warns of New SD-WAN Zero-Day Exploited in Attacks

Cisco has issued security updates and advisories regarding a critical zero-day authentication bypass vulnerability in its Catalyst SD-WAN Manager software that is actively being exploited in the wild.

Cisco Warns of New SD-WAN Zero-Day Exploited in Attacks

Critical Vulnerability in Catalyst SD-WAN Manager

Cisco has released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. The software, formerly known as SD-WAN vManage, is a network management solution allowing administrators to monitor and manage up to 6,000 SD-WAN devices from a single centralized dashboard.

According to the advisory published by the vendor, the issue affects all system deployments regardless of specific configuration. Found within the API session-based authentication management, the flaw enables unauthenticated attackers to gain remote access to vulnerable environments with full administrative rights.

Attack Mechanics and Indicators of Compromise

Cisco explained that the vulnerability arises from improper handling of URI encoding inside HTTP requests. This flaw permits a malicious request to successfully bypass authentication rules designed to restrict access to specific API endpoints. Threat actors leverage this by transmitting crafted HTTP requests directly to the API of targeted systems.

While specific details regarding active campaigns remain limited, the company provided indicators of compromise to help defenders. Threat actors have been observed utilizing %6a as the URI-encoded character for 'j' within malicious requests. Security teams are advised to check specific log files for related entries.

Investigation Guidance and Remediation

Security analysts and administrators investigating potentially compromised environments should examine the serviceproxy-access.log file located under the container paths, alongside vmanage-server.log files for entries related to j_security_check originating from unauthorized or unknown IP addresses.

Cisco strongly recommends that customers immediately upgrade to a fixed software release to completely remediate the vulnerability. Organizations seeking assistance to determine if their Catalyst SD-WAN Manager has been compromised can open a support case with the Cisco Technical Assistance Center after collecting necessary diagnostic files.

Part of a Broader Trend of SD-WAN Exploits

The discovery of CVE-2026-76504 marks the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the beginning of the year. Earlier incidents included information disclosure flaws and maximum-severity authentication bypass issues targeting controllers and managers.

Additional vulnerabilities earlier in the year, such as CVE-2026-20245 and CVE-2026-20262, were similarly exploited by malicious actors to gain deep root privileges on vulnerable enterprise deployments.

CISA Tracking and Ongoing Threat Landscape

In addition to the recent vulnerabilities, Cisco fixed another related flaw, CVE-2026-20262, earlier in the year. The Cybersecurity and Infrastructure Security Agency maintains catalogs reflecting numerous active disclosures over recent years.

Since November 2021, CISA has tagged a high volume of vendor vulnerabilities as actively exploited in the wild, underlining the continuous focus that sophisticated threat groups and ransomware operations place on enterprise networking gear.

Sources

Continue chronologically