10/01/2026, 07.41
by DanieleCEO and CTO at glacom.AI
Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp

Cisco SD-WAN Zero-Day: Critical Admin Bypass CVE-2026-76504

Cisco warns of a critical 9.8 CVSS vulnerability in Catalyst SD-WAN Manager. Attackers can gain full admin access via API bypass. Updates are urgent.
Cisco SD-WAN Zero-Day: Critical Admin Bypass CVE-2026-76504
Key points
  • A critical zero-day vulnerability (CVE-2026-76504) allows unauthenticated remote attackers to gain full admin privileges.
  • The flaw stems from improper URI encoding handling in the Catalyst SD-WAN Manager API.
  • Cisco confirmed active exploitation in September 2026, with no available workarounds.
  • Immediate software upgrades are required for all affected release trains to prevent total network compromise.

The integrity of enterprise network management has come under severe pressure following the discovery of a critical zero-day vulnerability in the Cisco Catalyst SD-WAN Manager. Identified as CVE-2026-76504, the flaw allows remote, unauthenticated attackers to bypass security protocols and assume the identity of the administrator user, granting them virtually unrestricted control over the managed network infrastructure.

The mechanics of the authentication bypass

At the core of this vulnerability is a failure in how the Catalyst SD-WAN Manager handles URI encoding within HTTP requests. The system's API session-based authentication management fails to correctly process these encoded characters, creating a loophole that allows a specifically crafted request to slip past authentication rules. These rules are designed to restrict access to sensitive API endpoints, but the encoding error effectively renders them invisible to the attacker.

Because the exploit requires no valid credentials, the barrier to entry is dangerously low. An attacker only needs the ability to send a malicious HTTP request to the Manager's API. Once the bypass is successful, the attacker is granted the privileges of the admin user. In a standard Cisco deployment, the admin user typically holds the netadmin role, which provides the authority to perform every possible operation on the device, from configuration changes to full system overrides.

Active exploitation and discovery

Cisco's Product Security Incident Response Team (PSIRT) confirmed that this is not a theoretical risk. The company became aware of active exploitation of CVE-2026-76504 in September 2026. The vulnerability was brought to light while the Cisco Technical Assistance Center (TAC) was managing a specific support case, highlighting how often critical flaws are discovered during the triage of anomalous system behavior.

While Cisco has issued a stern warning, the official advisory remains opaque regarding the scale of the breach. There is currently no public data on the total number of affected customers, the specific timeline of when the attacks began, or the identity of the threat actors involved. More importantly, the company has not disclosed what the attackers actually did once they gained administrative access to the targeted networks.

Risk assessment for internet-exposed systems

The vulnerability is particularly perilous for organizations that have exposed their SD-WAN Manager to the public internet. While internal deployments are also technically vulnerable, those with open ports facing the web are the primary targets for automated scanning and targeted attacks. The Catalyst SD-WAN Manager is a powerful tool, capable of monitoring and managing up to 6,000 SD-WAN devices from a single dashboard, meaning a single compromise can lead to the collapse of an entire global network architecture.

To help administrators identify if they have been targeted, Cisco suggests auditing the serviceproxy-access.log file located at /var/log/nms/containers/service-proxy/serviceproxy-access.log. Security teams should look for entries related to j_security_check originating from unauthorized or unknown IP addresses. Cisco noted that while their examples use %6a as the URI encoded character for j, attackers can use any encoded character to trigger the exploit.

Urgent remediation and versioning

There is a critical detail for IT managers: there are no workarounds for this flaw. The only way to secure the system is to apply the official software updates. This is especially urgent for those who updated their systems in May or June 2026 to fix other SD-WAN flaws (such as CVE-2026-20182, CVE-2026-20245, or CVE-2026-20262). Because CVE-2026-76504 is a separate issue, those previous patches do not provide protection against this current attack.

The following table outlines the first fixed releases for the primary release trains:

Release Train First Fixed Release
Earlier than 20.9 Migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

It is important to note that certain release trains, such as 20.10, 20.11, 20.13, 20.14, and 20.16, are not listed in the current fix table, and the advisory does not explicitly cover Cisco SD-WAN Cloud-Pro or the FedRAMP government deployment types.

Technical severity and CVSS scoring

The vulnerability has been assigned a CVSS score of 9.8 out of 10, placing it in the highest severity category. This score reflects the ease of exploitation (remote, no authentication required) and the devastating impact (full administrative control). For a business, this represents a total loss of confidentiality, integrity, and availability of the network management layer.

The vulnerability allows an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

For detailed technical specifications and the full list of affected versions, administrators should refer to the official Cisco Security Advisory or follow updates via The Hacker News.

Global business impact: USA, UK, and International Markets

For enterprises operating in the USA and UK, this vulnerability transcends a simple technical patch; it enters the realm of regulatory compliance and risk management. In the United States, the SEC's heightened requirements for cybersecurity disclosure mean that a breach of this magnitude—where administrative control of the entire network is lost—could potentially trigger mandatory reporting if deemed material to investors.

In the UK, the focus remains on the NIS2-style frameworks and the GDPR. A compromise of the SD-WAN Manager could allow attackers to intercept data traffic or disrupt essential services, leading to significant fines if the organization is found to have neglected critical security updates. Given that there is no workaround, the failure to patch a 9.8 CVSS vulnerability known to be actively exploited could be viewed as a failure of due diligence by regulators.

Globally, the reliance on SD-WAN for connecting remote offices and cloud environments means that this flaw targets the very backbone of the modern distributed enterprise. Companies using Cisco for their global connectivity must treat this as a priority-one event. The lack of a workaround means that the window of exposure is absolute until the update is applied, making the speed of deployment the only viable defense strategy.

FAQ

What is CVE-2026-76504?

It is a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows unauthenticated remote attackers to gain full admin privileges via an API authentication bypass.

How do I know if my system is at risk?

Any Cisco Catalyst SD-WAN Manager deployment is vulnerable regardless of configuration, but those exposed to the internet are at the highest risk.

Can I use a workaround instead of updating?

No, Cisco has explicitly stated that there are no workarounds available for this vulnerability.

Does the May or June 2026 update protect me?

No, this vulnerability is separate from the flaws fixed in May and June. You must update to the specific fixed releases listed for CVE-2026-76504.


Sources: Thehackernews, Bleepingcomputer, Sec ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp
Printable version
CLOSE X
Share this story
See also
Apple, IBM and AI Tools: Critical Vulnerabilities Hit Global Tech
New security alerts reveal critical flaws in Apple OS, IBM Guardium, and FlowiseAI, highlighting a surge in active exploitation and data exposure risk…
29/09/2026 19:41
Critical Security Flaws Hit Fortinet, n8n, and Tenable Systems
New alerts reveal critical vulnerabilities in Fortinet, n8n, and Tenable. Learn how patch bypasses and RCE risks impact global business infrastructure…
29/09/2026 19:35
Critical Security Flaws Hit Elastic, Dell, and Wazuh Platforms
New vulnerabilities in Elastic, Dell, and ServiceNow expose enterprises to privilege escalation and DoS attacks. Learn the risks and necessary mitigat…
29/09/2026 19:33
Critical Security Flaws Hit Apache, GitLab and PaperCut Systems
New security alerts reveal critical vulnerabilities in Apache Tomcat, GitLab, and PaperCut, exposing businesses to remote code execution and data leak…
29/09/2026 19:33
ClosedQuorum: The First AI-Driven Autonomous Windows Malware
Cisco Talos discovers ClosedQuorum, a Windows malware that replaces human C2 servers with a voting system of four AI models to automate cyber attacks.
29/09/2026 19:28


Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now