Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco says attackers are exploiting critical SD-WAN Manager auth-bypass zero-day CVE-2026-76504.
Cisco released fixes for CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that unauthenticated attackers are actively exploiting to gain administrator privileges. Improper URI-encoding handling lets a crafted HTTP request skip an authentication rule on a specific API endpoint, and every deployment is affected regardless of configuration. Cisco PSIRT learned of exploitation in September 2026 and cited malicious use of %6a for the character "j" plus suspicious j_security_check entries in serviceproxy-access.log and vmanage-server.log. Fixed versions include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1; it is the fifth SD-WAN zero-day exploited in 2026, after CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262.
- CVE-2026-76504 gives unauthenticated remote attackers admin access.
- The bypass abuses URI encoding in HTTP API requests.
- Cisco confirmed active exploitation in September 2026.
- Fixed releases include 20.9.10.1, 20.12.8.2, and 20.18.4.1.
- It is the fifth exploited Cisco SD-WAN zero-day of 2026.
Vulnerabilities mentionedAll →
- CVE-2026-2012710.088%Authentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, Validatorpublished · Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) KEV
- CVE-2026-2018210.0
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 20.12.8.2 | than 20.9 Migrate to a fixed release. 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 F |
| ipv4 | 20.15.6.1 | te to a fixed release. 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 Fifth actively ex |
| ipv4 | 20.18.4.1 | lease. 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 Fifth actively exploited SD-WAN z |
| ipv4 | 20.9.10.1 | Release Earlier than 20.9 Migrate to a fixed release. 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2 |
| ipv4 | 26.1.2.1 | 9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 Fifth actively exploited SD-WAN zero-day in 202 |
Full article478 words · extracted from bleepingcomputer.com · click to collapse

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
The CVE-2026-76504 vulnerability affects all deployments regardless of system configuration, was found in API session-based authentication management, and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
"This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint," Cisco added.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system."
While the company didn't share further details regarding attacks exploiting CVE-2026-76504, it shared indicators of compromise (IOCs) warning admins that threat actors are using %6a as the URI-encoded character "j" in malicious requests.
It also advised security teams investigating potentially compromised SD-WAN systems to check the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/for entries related to j_security_check from unknown or unauthorized IP addresses.
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," it added, advising admins first to collect admin-tech files to support the review.
| Cisco Catalyst SD-WAN Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Fifth actively exploited SD-WAN zero-day in 2026
CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the start of the year.
Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February, exploited since at least 2023, and tagged a maximum-severity Catalyst SD-WAN Controller auth bypass flaw (CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.
More recently, in early June, Cisco warned of two more SD-WAN zero-days (CVE-2026-20245 and CVE-2026-20262) that attackers exploited to gain root privileges on vulnerable systems.
Since November 2021, the Cybersecurity and Infrastructure Security Agency (CISA) has tagged 90 Cisco vulnerabilities as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.