Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco says attackers are exploiting critical SD-WAN Manager auth-bypass zero-day CVE-2026-76504.
Cisco released fixes for CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that unauthenticated attackers are actively exploiting to gain administrator privileges. Improper URI-encoding handling lets a crafted HTTP request skip an authentication rule on a specific API endpoint, and every deployment is affected regardless of configuration. Cisco PSIRT learned of exploitation in September 2026 and cited malicious use of %6a for the character "j" plus suspicious j_security_check entries in serviceproxy-access.log and vmanage-server.log. Fixed versions include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1; it is the fifth SD-WAN zero-day exploited in 2026, after CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262.