[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fC7utjqTZx-P65qaXxLlV47McMFbE2bM7VmyU3DZTZYY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"e90d588f-96aa-4c53-929f-e82aa8b42cc3","critical-cisco-sd-wan-auth-bypass-exploited-in-the-wild-1790857283100","dd9bd6be-dfd1-4ca2-bc3b-88088d839d47","Critical Cisco SD-WAN Auth Bypass Exploited in the Wild","CVE-2026-76504 exposes a fundamental flaw in how Cisco Catalyst SD-WAN Manager handles URI encoding, allowing unauthenticated attackers to craft malicious HTTP requests that completely bypass authentication and gain administrative access. This is particularly dangerous because SD-WAN Manager sits at the heart of enterprise network infrastructure — admin-level compromise means an attacker can manipulate routing, intercept traffic, or pivot laterally across the entire WAN fabric. The CVSS score of 9.8 reflects how low the barrier to exploitation is: no credentials, no special position on the network, just a crafted HTTP request. CISA's addition to the KEV catalog confirms this is not theoretical — real attackers are actively weaponizing this flaw, making delayed patching an immediate operational risk.","**Immediate actions:**\n- Apply Cisco's official patch immediately and prioritize internet-facing SD-WAN Manager instances ahead of the October 3, 2026 federal deadline.\n- Restrict management-plane access to SD-WAN Manager behind a VPN or jump host, blocking direct internet exposure to the management interface.\n- Hunt for indicators of compromise using Cisco's guidance, specifically reviewing logs for anomalous `j_security_check` API calls from unexpected source IPs.\n\n**Detection measures:**\n- Deploy a WAF or IDS rule to detect and alert on malformed or suspicious URI-encoded requests targeting SD-WAN Manager authentication endpoints.\n- Enable centralized logging for all SD-WAN Manager authentication events and route alerts to your SIEM for real-time anomaly detection.\n- Conduct a retrospective log review covering the past 90 days to identify any exploitation attempts that may have occurred prior to detection.\n\n**Long-term improvements:**\n- Establish an emergency patching SLA (e.g., 24–72 hours) for CVSS 9.0+ vulnerabilities affecting network infrastructure components.\n- Maintain a continuously updated inventory of all network appliances, firmware versions, and management interfaces exposed to internal or external networks.\n- Implement network segmentation to isolate SD-WAN management planes from general user traffic and limit blast radius in the event of a future compromise.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 AU-6: Audit Record Review and Analysis","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","NIST CSF RS.MI-3: Newly Identified Vulnerabilities Mitigated","CISA BOD 22-01: Known Exploited Vulnerabilities Catalog","ITIL 4: Change Enablement (Emergency Change Procedure)","ISO\u002FIEC 27001 A.12.6.1: Management of Technical Vulnerabilities","published","2026-10-01T12:21:23.391158+00:00","2026-10-01T12:21:22.632+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fcisa-adds-exploited-cisco-catalyst-sd.html","cisa-adds-exploited-cisco-catalyst-sd-wan-manager-auth-bypass-to-kev-346b23","CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"3dbe4660-701c-41d5-8043-c69158524395","2026-10-01","afternoon","ThreatNoir Afternoon Brief — October 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-10-01\u002Fthreatnoir-afternoon-brief-2026-10-01.mp3"]