Overview
- Cisco confirmed on September 30 that CVE-2026-76504 was being actively exploited and released fixed Catalyst SD‑WAN Manager releases to stop the flaw.
- The vulnerability comes from improper handling of URI encoding in the Manager’s login-session API, allowing a crafted request to bypass authentication and act as the admin user with netadmin privileges.
- Cisco lists fixed releases for multiple release trains and says there is no workaround, and it recommends upgrading or restricting Manager access to trusted hosts until systems are patched.
- The company published indicators of compromise — notably URI-encoded variants such as %6a and j_security_check log entries — and told customers to collect admin-tech logs and open TAC cases for suspected intrusions because the advisory does not say whether upgrades remove attacker persistence.
- This zero‑day continues a 2026 pattern of SD‑WAN management‑plane targeting, which raises operational risk for internet‑exposed controllers and makes frequent patching and proactive log hunting a practical necessity for network operators.