Cisco Warns of New SD-WAN Zero-Day Exploited in Attacks
Cisco has issued security updates and advisories regarding a critical zero-day authentication bypass vulnerability in its Catalyst SD-WAN Manager software that is actively being exploited in the wild.

Critical Vulnerability in Catalyst SD-WAN Manager
Cisco has released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. The software, formerly known as SD-WAN vManage, is a network management solution allowing administrators to monitor and manage up to 6,000 SD-WAN devices from a single centralized dashboard.
According to the advisory published by the vendor, the issue affects all system deployments regardless of specific configuration. Found within the API session-based authentication management, the flaw enables unauthenticated attackers to gain remote access to vulnerable environments with full administrative rights.
Attack Mechanics and Indicators of Compromise
Cisco explained that the vulnerability arises from improper handling of URI encoding inside HTTP requests. This flaw permits a malicious request to successfully bypass authentication rules designed to restrict access to specific API endpoints. Threat actors leverage this by transmitting crafted HTTP requests directly to the API of targeted systems.
While specific details regarding active campaigns remain limited, the company provided indicators of compromise to help defenders. Threat actors have been observed utilizing %6a as the URI-encoded character for 'j' within malicious requests. Security teams are advised to check specific log files for related entries.
Investigation Guidance and Remediation
Security analysts and administrators investigating potentially compromised environments should examine the serviceproxy-access.log file located under the container paths, alongside vmanage-server.log files for entries related to j_security_check originating from unauthorized or unknown IP addresses.
Cisco strongly recommends that customers immediately upgrade to a fixed software release to completely remediate the vulnerability. Organizations seeking assistance to determine if their Catalyst SD-WAN Manager has been compromised can open a support case with the Cisco Technical Assistance Center after collecting necessary diagnostic files.
Part of a Broader Trend of SD-WAN Exploits
The discovery of CVE-2026-76504 marks the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the beginning of the year. Earlier incidents included information disclosure flaws and maximum-severity authentication bypass issues targeting controllers and managers.
Additional vulnerabilities earlier in the year, such as CVE-2026-20245 and CVE-2026-20262, were similarly exploited by malicious actors to gain deep root privileges on vulnerable enterprise deployments.
CISA Tracking and Ongoing Threat Landscape
In addition to the recent vulnerabilities, Cisco fixed another related flaw, CVE-2026-20262, earlier in the year. The Cybersecurity and Infrastructure Security Agency maintains catalogs reflecting numerous active disclosures over recent years.
Since November 2021, CISA has tagged a high volume of vendor vulnerabilities as actively exploited in the wild, underlining the continuous focus that sophisticated threat groups and ransomware operations place on enterprise networking gear.
Sources
- BleepingComputerCisco warns of new SD-WAN zero-day exploited in attacks