Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco has released security updates for CVE-2026-76504, a critical zero-day in Catalyst SD-WAN Manager that is being actively exploited to gain admin privileges. The flaw affects all deployments and lets unauthenticated attackers bypass authentication through crafted HTTP requests, with Cisco urging customers to upgrade and check logs for signs of compromise. #Cisco #CatalystSDWANManager #CVE202676504

Keypoints

  • Cisco fixed a critical zero-day in Catalyst SD-WAN Manager.
  • CVE-2026-76504 is being actively exploited to escalate to admin privileges.
  • The flaw affects all deployments and is caused by improper URI encoding handling.
  • Attackers can bypass authentication by sending crafted HTTP requests to the API.
  • Cisco advises upgrading and reviewing logs for j_security_check activity from unknown IPs.

Read More: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/