Skip to content
Cisco Patches Exploited Catalyst SD-WAN Zero

Cisco Patches Exploited Catalyst SD-WAN Zero

Securityweek •Ionut Arghire • October 1, 2026

Cisco on Wednesday rolled out urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager that has been exploited in the wild.

Tracked as CVE-2026-76504 (CVSS score of 9.8), the flaw impacts the API session-based authentication mechanism and could allow remote, unauthenticated attackers to gain administrative access to a vulnerable system.

“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company warned .

According to Cisco, the issue resides in the improper handling of URI encoding in an HTTP request, allowing attacker requests to reach a restricted API endpoint.

“An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user,” Cisco explains.

All Catalyst SD-WAN Manager deployments are affected, regardless of their configuration, and there are no workarounds.

CVE-2026-76504 was resolved in Catalyst SD-WAN versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Cisco-managed SD-WAN deployments have been patched as well.

Cisco has released indicators of compromise (IoCs) to help security teams hunt for potential exploitation attempts, and published general recommendations for hardening at-risk systems.

On Wednesday, the US cybersecurity agency CISA added the security defect to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days.

Neither Cisco nor CISA has shared details on the security bug’s in-the-wild exploitation.

“ Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited Vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone – this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” WatchTowr head of threat intelligence Jake Knott said.

“None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target. Organizations running Catalyst SD-WAN Manager should upgrade to a fixed release immediately and follow vendor guidance, including hunting for POST requests to any URL-encoded variants of ‘/j_security_check’ and reviewing instances for signs exploitation has already occurred,” Knott added.

Related: Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

ShinyHunters Defiant After FBI Calls on Members to Come Forward

Reco Raises $55 Million for Agentic Security

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

DC Health Agency Exposes 400,000 Beneficiary Records

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders

FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Flipboard Whatsapp Whatsapp Email

Extracted Entities

Attack Types (1)

Companies (1)