[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb4eEQDjIRunFfjjwhA5uIAfItES0C41kEoQPuBo81RM":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"51bbf76e-a6c8-4708-9eee-54a5a272bfdd","Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability","cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability-1b2406","The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability appeared first on SecurityWeek.","Cisco has released patches for a critical authentication bypass vulnerability (CVE-2026-76504) in its Catalyst SD-WAN Manager, which has been actively exploited in the wild. The flaw, with a CVSS score of 9.8, allows unauthenticated attackers to gain administrative privileges by sending crafted HTTP requests. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch it immediately.","Cisco patches exploited Catalyst SD-WAN Manager zero-day vulnerability (CVE-2026-76504).","Cisco on Wednesday rolled out urgent patches for a critical authentication bypass in Catalyst SD-WAN Manager that has been exploited in the wild. Tracked as CVE-2026-76504 (CVSS score of 9.8), the flaw impacts the API session-based authentication mechanism and could allow remote, unauthenticated attackers to gain administrative access to a vulnerable system. “In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company warned. According to Cisco, the issue resides in the improper handling of URI encoding in an HTTP request, allowing attacker requests to reach a restricted API endpoint. “An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user,” Cisco explains. All Catalyst SD-WAN Manager deployments are affected, regardless of their configuration, and there are no workarounds.Advertisement. Scroll to continue reading. CVE-2026-76504 was resolved in Catalyst SD-WAN versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Cisco-managed SD-WAN deployments have been patched as well. Cisco has released indicators of compromise (IoCs) to help security teams hunt for potential exploitation attempts, and published general recommendations for hardening at-risk systems. On Wednesday, the US cybersecurity agency CISA added the security defect to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days. Neither Cisco nor CISA has shared details on the security bug’s in-the-wild exploitation. “Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited Vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone – this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” WatchTowr head of threat intelligence Jake Knott said. “None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target. Organizations running Catalyst SD-WAN Manager should upgrade to a fixed release immediately and follow vendor guidance, including hunting for POST requests to any URL-encoded variants of ‘\u002Fj_security_check’ and reviewing instances for signs exploitation has already occurred,” Knott added. Related: Google: AI Is Changing the Pace and Profile of Vulnerability Discovery Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary Records Latest News 500,000 Active Credentials Left Exposed on GitHubGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersFTC is Investigating OpenAI and Anthropic Over Possible Risks to ConsumersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksChrome, Firefox Updates Patch Over 100 VulnerabilitiesAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDavid Cass has joined Grayscale Investments as Chief Risk Officer.Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FCisco-network-switch-exploit.webp","2026-10-01T08:26:03+00:00","2026-10-01T10:00:09.541167+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"Catalyst SD-WAN Manager","product",{"name":22,"type":23},"Cisco","vendor",{"name":25,"type":26},"SD-WAN","technology",{"name":28,"type":20},"API",{"name":30,"type":20},"HTTP",{"name":32,"type":20},"CISA KEV","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":58,"value":59,"context":60},"cve","CVE-2026-76504","Cisco Catalyst SD-WAN Manager authentication bypass vulnerability"]