Security · October 3, 2026
Also published in Nederlands, 日本語, 中文, Indonesia, ไทย, Español, עברית, Русский, Português (Brasil), Italiano
Cisco Warns of Actively Exploited Zero-Day in Catalyst SD-WAN Manager
Cisco has issued a security advisory that a zero-day vulnerability in its Catalyst SD-WAN Manager is being exploited in the wild. The flaw, tracked as CVE-2026-76504, allows remote attackers to invoke the application programming interface with administrative privileges without authentication. The vulnerability resides in the API endpoint that handles login sessions and carries a CVSS score of 9.8, classifying it as critical. Cisco’s Product Security Incident Response Team confirmed that exploitation began in September 2026, when a support case revealed an active attack before a patch was available. The issue stems from improper URI encoding in HTTP requests, enabling a specially crafted request to bypass authentication checks. An attacker can send the request without any credentials and assume the netadmin role, which grants full control over the device. All configurations of the SD-WAN Manager are affected, and the company warns that any system exposed to the internet faces a high risk of compromise.
Cisco has released patches across multiple release trains, with the first fixed versions being 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Earlier releases must be upgraded to the corresponding fixed release. Cisco Managed Cloud was patched in release 20.15.605. The advisory notes that previous vulnerabilities such as CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262 are older and do not replace the need for this update. Organizations that applied updates in May or June 2026 must apply the fix again. Cisco recommends restricting internet access, allowing only trusted hosts, and placing the control component behind a firewall, following hardening guidance that advises against opening ports 443, 22 and 830 directly to the internet. To detect signs of exploitation, administrators should search logs for the path j_security_check, which appears as /%6a_security_check when encoded, and examine entries in /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log, especially those beginning with viptela-reserved-.
Because any character can be encoded, false positives may occur, so activity must be compared against normal patterns. The advisory does not state whether patching will remove an attacker who already accessed the system, and previous guidance indicated that updating alone is insufficient. Cisco advises retaining request logs from the admin-tech command before upgrading and opening a severity‑3 case with the TAC, referencing CVE-2026-76504 in the subject line. In 2026, eight Cisco SD-WAN vulnerabilities have been added to the CISA Known Exploited Vulnerabilities catalog.