Skip to content
Cisco Catalyst SD-WAN Manager Zero-Day Exploited by Attackers

Cisco Catalyst SD-WAN Manager Zero-Day Exploited by Attackers

First seen 30 Sep 2026, 17:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 18:35 UTC
  • •CVE-2026-76504 is a critical zero-day vulnerability in Cisco's SD-WAN Manager.
  • •Attackers can exploit this flaw to gain admin privileges remotely without authentication.
  • •Cisco recommends immediate software updates to mitigate the risk.

Cisco has disclosed a critical zero-day vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager, which is actively being exploited by attackers to gain admin privileges. This flaw, due to improper URI encoding handling in API session-based authentication, allows unauthenticated remote access to affected systems. All deployments of the Catalyst SD-WAN Manager are vulnerable, regardless of configuration. Cisco has released security updates to mitigate this vulnerability and strongly advises customers to upgrade immediately. The vulnerability was reported to Cisco's PSIRT in September 2026, and indicators of compromise (IOCs) include the use of '%6a' in malicious HTTP requests. This marks the fifth actively exploited SD-WAN zero-day vulnerability identified in 2026, following several others earlier in the year. Cisco has not provided specific details on the ongoing attacks exploiting this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-02-25
CVE-2026-20127 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-14
CVE-2026-20182 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-20245 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-15
CVE-2026-20262 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-30
CVE-2026-76504 published
Cisco disclosed a critical zero-day vulnerability in Catalyst SD-WAN Manager, affecting all deployments.
Bleepingcomputer
2026-09-30
CISA KEV addition
CVE-2026-76504 was added to the CISA KEV catalog due to active exploitation.
Bleepingcomputer

More articles in this cluster (4)

Following this threat?

Track CVE-2026-20127 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which systems are affected?
All deployments of Cisco Catalyst SD-WAN Manager are vulnerable to CVE-2026-76504.
Is this vulnerability being actively exploited?
Yes, Cisco confirmed that CVE-2026-76504 is being actively exploited in the wild.
What should I do to protect my systems?
Upgrade to the latest software release provided by Cisco to remediate this critical vulnerability.