Threat Intelligence

Cisco Confirms Active Exploitation of Critical Flaw in SD-WAN Manager

The Hacker News · 1 Oct 2026
Key Takeaway If your business uses Cisco Catalyst SD-WAN Manager, apply the latest fixed release immediately and ensure the management interface is not exposed to the internet.

Cisco has issued an advisory confirming active exploitation of a critical zero-day vulnerability in its Catalyst SD-WAN Manager, the system used to manage Cisco SD-WAN networks. Tracked as CVE-2026-76504 and rated 9.8 out of 10 in severity, the flaw allows a remote attacker with no login credentials to interact with the Manager's API as if they were the admin user, who by default has full control of the device.

The issue stems from how the Manager handles URI encoding in HTTP requests, which lets a specially crafted request bypass an authentication rule meant to restrict access to a single API endpoint. Cisco says any Manager exposed to the internet is at risk, and the flaw affects the product regardless of configuration. Cisco's security team became aware of active exploitation in September 2026 while investigating a separate support case, though it has not disclosed how many customers were affected or what attackers did with access gained.

Fixed software releases are available and there is no workaround, meaning affected organisations must upgrade promptly. This vulnerability is separate from three other Cisco SD-WAN flaws patched earlier this year, and systems updated only for those earlier fixes remain vulnerable to this new issue.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.