Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Cisco warns of actively exploited SD-WAN zero-day

Cisco has released security updates for a critical zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2026-76504. The company says it became aware of active exploitation in September 2026 and recommends customers upgrade to a fixed software release.

The flaw affects all deployments regardless of system configuration. It stems from how the software handles URI encoding in HTTP requests to API session-based authentication management. Cisco says an unauthenticated remote attacker could send a crafted request to bypass an authentication rule and gain administrator privileges. The company has not shared further details about the attacks.

Cisco said attackers are using %6a, the URI-encoded character for “j,” in malicious requests. For investigations, it advised checking serviceproxy-access.log under /var/log/nms/containers/service-proxy and vmanage-server.log under /var/log/nms/ for j_security_check entries from unknown or unauthorized IP addresses. Customers can contact Cisco TAC for help assessing a possible compromise; Cisco advised collecting admin-tech files first.

Cisco’s advisory comes amid a series of exploited SD-WAN flaws. BleepingComputer reports CVE-2026-76504 is the fifth SD-WAN zero-day exploited in the wild since the start of the year. Cisco previously disclosed active exploitation of four other SD-WAN flaws in February, May, and early June. The source also reports that CISA has tagged 90 Cisco vulnerabilities as exploited in the wild since November 2021.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.