Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
The CVE-2026-76504 vulnerability affects all deployments regardless of system configuration, was found in API session-based authentication management, and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
"This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint," Cisco added.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system."
While the company didn't share further details regarding attacks exploiting CVE-2026-76504, it shared indicators of compromise (IOCs) warning admins that threat actors are using %6a as the URI-encoded character "j" in malicious requests.
It also advised security teams investigating potentially compromised SD-WAN systems to check the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/for entries related to j_security_check from unknown or unauthorized IP addresses.
"For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," it added, advising admins first to collect admin-tech files to support the review.
| Cisco Catalyst SD-WAN Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Fifth actively exploited SD-WAN zero-day in 2026
CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the start of the year.
Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February, exploited since at least 2023, and tagged a maximum-severity Catalyst SD-WAN Controller auth bypass flaw (CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.
More recently, in early June, Cisco warned of two more SD-WAN zero-days (CVE-2026-20245 and CVE-2026-20262) that attackers exploited to gain root privileges on vulnerable systems.
Today, the Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.
Since November 2021, CISA has tagged 90 Cisco vulnerabilities as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.
References in this story
- NVD - Home nvd.nist.gov
- Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability sec.cloudapps.cisco.com A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This…
- Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023 www.bleepingcomputer.com Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise…
- Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks www.bleepingcomputer.com Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on…
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks www.bleepingcomputer.com On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation.
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks www.bleepingcomputer.com Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges.
- CISA Adds One Known Exploited Vulnerability to Catalog | CISA www.cisa.gov
- Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
- Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…



