Cisco has disclosed a critical zero-day vulnerability in its Catalyst SD-WAN Manager product that attackers are already using to seize administrative control of affected systems. The flaw is tracked as CVE-2026-76504 and affects every deployment of the software, regardless of how it is configured. Cisco's Product Security Incident Response Team said it learned of active exploitation in September 2026 and is urging customers to move to a fixed software release.
Catalyst SD-WAN Manager, previously called SD-WAN vManage, is network management software that allows administrators to monitor and manage as many as 6,000 SD-WAN devices from one dashboard. Cisco said the problem lies in API session-based authentication management. The company attributed the bug to improper handling of URI encoding in HTTP requests, which lets a request slip past an authentication rule meant to limit access to a specific API endpoint. By sending a crafted HTTP request to the affected system's API, an unauthenticated attacker can reach the system remotely and operate with admin privileges.
Cisco did not detail the attacks it has observed, but it published indicators of compromise for defenders. The company warned that threat actors are using %6a, the URI-encoded form of the character "j," in malicious requests. Security teams checking potentially compromised SD-WAN systems were advised to review the serviceproxy-access.log file under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/ for entries tied to j_security_check from unknown or unauthorized IP addresses. Cisco said customers can open a case with its Technical Assistance Center for help determining whether a Catalyst SD-WAN Manager instance has been compromised, and it advised collecting admin-tech files first to support the review.
The vulnerability is the fifth SD-WAN zero-day that attackers have exploited in the wild since the start of the year. Cisco patched an SD-WAN Manager information disclosure flaw, CVE-2026-20127, in February after exploitation dating to at least 2023. In May, the company flagged a maximum-severity Catalyst SD-WAN Controller authentication bypass, CVE-2026-20182, as actively exploited in zero-day attacks used to gain admin privileges on unpatched devices. In early June, Cisco warned of two more SD-WAN zero-days, CVE-2026-20245 and CVE-2026-20262, that attackers used to obtain root privileges.
The Cybersecurity and Infrastructure Security Agency also added CVE-2026-76504 to its Known Exploited Vulnerabilities Catalog. CISA ordered U.S. federal agencies to secure their systems against attacks exploiting the flaw by Saturday, October 3. Since November 2021, the agency has tagged 90 Cisco vulnerabilities as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.
More cybersecurity news from TechManNews.





