Particle.news

Cisco SD‑WAN Manager Zero‑Day Lets Unauthenticated Attackers Reach Admin API

Apply Cisco's patch immediately to stop unauthenticated requests from bypassing login and taking control of SD‑WAN Manager.

Overview

  • CVE-2026-76504 is a critical authentication‑bypass bug in Cisco Catalyst SD‑WAN Manager that lets a remote attacker send a crafted HTTP request to the Manager API and act as the admin user.
  • Cisco confirmed active exploitation and published fixes and guidance on Sept. 30, 2026, and the company says fixed releases are available but there is no workaround.
  • Cisco published indicators of compromise that include URI‑encoded variants of j_security_check (for example %6a) and told admins to review /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for suspicious entries.
  • Until on‑prem Managers are updated Cisco urges restricting internet access to those controllers, allowing only trusted hosts, and notes cloud‑hosted Cisco SD‑WAN environments are already fixed in some builds.
  • This is the fifth actively exploited SD‑WAN zero‑day in 2026, and Cisco warns that applying an update alone may not evict an intruder so affected customers should collect admin‑tech output and open a TAC case for incident review.