BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: Cisco SD-WAN Zero-Day CVE-2026-76504 Exploited in Attacks

The Cisco SD-WAN zero-day tracked as CVE-2026-76504 is being actively exploited, creating an urgent patching priority for organizations that use Cisco Catalyst SD-WAN Manager. Cisco published a critical advisory on September 30, 2026, warning that an unauthenticated remote attacker could bypass authentication and access an affected system with administrator privileges.

What happened

Cisco released security updates for CVE-2026-76504 after its Product Security Incident Response Team became aware of active exploitation in September 2026. The vulnerability affects the API session-based authentication management in Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage.

The flaw is caused by improper handling of URI encoding in an HTTP request. Cisco says an attacker can send a crafted request to the system API, bypass an authentication rule, and access the API as an administrator.

CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities Catalog on September 30. Federal civilian agencies were directed to remediate the flaw by October 3, 2026. CISA’s deadline applies to federal agencies, but the catalog is also a strong warning for private organizations because inclusion requires evidence of real-world exploitation.

What is confirmed

  • Cisco rates CVE-2026-76504 critical with a CVSS score of 9.8.
  • The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration.
  • An unauthenticated remote attacker can exploit the flaw to obtain administrator-level API access.
  • Cisco confirmed that it became aware of active exploitation in September 2026.
  • Cisco has released fixed software versions and says there are no workarounds that fully address the vulnerability.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog.

What remains unverified

Cisco has not publicly identified the threat actors exploiting the vulnerability, the number of affected organizations, or the attackers’ broader objectives. The company has not said whether the observed activity is connected to ransomware, espionage, or another campaign.

A vulnerable product should not automatically be treated as compromised. Organizations must review logs and other evidence to determine whether exploitation occurred in their environments.

Who and what is affected

CVE-2026-76504 affects Cisco Catalyst SD-WAN Manager across all deployment configurations. This platform provides centralized administration for SD-WAN environments, so unauthorized administrator access could give an attacker significant visibility and control over network management.

Cisco lists the following first fixed releases:

  • Release 20.9: 20.9.10.1
  • Release 20.12: 20.12.8.2
  • Release 20.15: 20.15.6.1
  • Release 20.18: 20.18.4.1
  • Release 26.1: 26.1.2.1
  • Release 26.2: 26.2.1

Deployments running releases earlier than 20.9 must migrate to a fixed release. Cisco said it addressed the issue in its managed cloud environment with release 20.15.605 and that no customer action is required for that environment.

Why this Cisco SD-WAN vulnerability matters

SD-WAN management systems are high-value targets because they control connectivity across offices, data centers, cloud services, and remote locations. Administrator access could allow an intruder to change configurations, observe network information, create persistence, or support movement into other systems.

Small and midsize businesses may not operate Catalyst SD-WAN Manager directly, but their internet provider, managed service provider, or network integrator may use it. Business owners should confirm whether a technology partner manages Cisco SD-WAN infrastructure on their behalf and request written confirmation of patch status.

Practical defensive actions

Upgrade to a fixed release immediately

Organizations using Catalyst SD-WAN Manager should compare their installed version with Cisco’s fixed-release table and schedule an emergency upgrade. Cisco states that there are no workarounds that fully resolve the flaw.

Restrict management access

For on-premises deployments, prevent direct access from unsecured networks whenever possible. If internet access is required, restrict connections to known, trusted hosts and place SD-WAN control components behind filtering devices such as firewalls.

Review Cisco’s indicators of compromise

Cisco recommends auditing the serviceproxy-access.log file for unexpected requests to j_security_check, including requests that use URI-encoded characters such as %6a. Security teams should also review vmanage-server.log for suspicious requests involving accounts whose names begin with viptela-reserved-.

Because similar log entries can occur during normal activity, findings should be compared with expected network behavior and authorized source addresses. Preserve relevant logs before making major system changes.

Contact Cisco TAC if compromise is suspected

Cisco advises customers that need help determining whether exploitation occurred to open a Technical Assistance Center case and include CVE-2026-76504 in the title. Collect the requested administrative diagnostic files before opening the case when possible.

Verify third-party remediation

Businesses that outsource networking should ask their provider whether Catalyst SD-WAN Manager is present, which release is running, when the fix was applied, and whether the recommended log review found suspicious activity. A verbal statement that systems are monitored is not a substitute for version and investigation details.

Prepare for credential and configuration recovery

If exploitation is confirmed, incident responders should evaluate administrator credentials, API sessions, configuration changes, connected edge devices, and downstream systems. Simply installing the patch may not remove access that an attacker established before remediation.

Sources

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment