Particle.news

Cisco Patches Actively Exploited SD‑WAN Manager Zero‑Day

The bug lets unauthenticated actors take admin API control by abusing URI‑encoded login requests, so organizations must upgrade or lock down exposed management interfaces immediately.

Overview

  • Cisco confirmed on September 30 that CVE-2026-76504 was being actively exploited and released fixed Catalyst SD‑WAN Manager releases to stop the flaw.
  • The vulnerability comes from improper handling of URI encoding in the Manager’s login-session API, allowing a crafted request to bypass authentication and act as the admin user with netadmin privileges.
  • Cisco lists fixed releases for multiple release trains and says there is no workaround, and it recommends upgrading or restricting Manager access to trusted hosts until systems are patched.
  • The company published indicators of compromise — notably URI-encoded variants such as %6a and j_security_check log entries — and told customers to collect admin-tech logs and open TAC cases for suspected intrusions because the advisory does not say whether upgrades remove attacker persistence.
  • This zero‑day continues a 2026 pattern of SD‑WAN management‑plane targeting, which raises operational risk for internet‑exposed controllers and makes frequent patching and proactive log hunting a practical necessity for network operators.