Cisco warned that attackers are actively exploiting CVE-2026-76504, a critical zero-day in Cisco Catalyst SD-WAN Manager that can let a remote unauthenticated attacker use the API as the admin user. Cisco has released fixed versions and advised customers to restrict internet exposure, check for signs of compromise, and upgrade immediately. #CVE-2026-76504 #CiscoCatalystSDWANManager #CiscoTAC #CISA
Keypoints
- CVE-2026-76504 is an actively exploited zero-day in Cisco Catalyst SD-WAN Manager.
- The flaw can let a remote attacker bypass authentication and access the API as admin.
- It has a CVSS score of 9.8 and no workaround is available.
- Cisco says exposed internet-facing Managers are at risk and should be restricted.
- Customers should upgrade to the first fixed release for their release train and review logs for suspicious j_security_check activity.
Read More: https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html