Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    October 3, 2026

    Cboe wants to turn VIX into a never-ending trade: Crypto Daily

    October 3, 2026

    ‘Nature-Based’ Solutions Could Save Insurers and Policyholders Billions

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
    • Cboe wants to turn VIX into a never-ending trade: Crypto Daily
    • ‘Nature-Based’ Solutions Could Save Insurers and Policyholders Billions
    • What do Britain’s death-penalty cheerleaders have to say about Christa Pike? | Maya Foa
    • Yemen’s army claims over 1,500 Houthi casualties in past 24 hours | Houthis News
    • Green party conference continues with cost of living on the agenda – UK politics live | Politics
    • Chewy Promo Codes: $20 Off October 2026
    • CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 01, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.

    The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with the privileges of the admin user.

    “Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request,” CISA said.

    Cybersecurity

    Successful exploitation could allow an attacker to sidestep authentication by sending a crafted HTTP request to the API of the affected system, and gain access to the API as the admin user.

    The development comes after Cisco said it became aware of active exploitation of CVE-2026-76504 in September 2026. The networking equipment maker has made available indicators of compromise (IoCs) that customers can use to check if their environments are impacted –

    • Audit “/var/log/nms/containers/service-proxy/serviceproxy-access.log” for entries that are related to j_security_check from unknown or unauthorized IP addresses
    • Audit “/var/log/nms/vmanage-server.log” for entries that are related to j_security_check from unknown or unauthorized IP addresses, specifically being called for users that include names starting with “viptela-reserved-“

    Cisco did not provide any details about the exploitation activity, who is behind it, how many organizations have been compromised thus far, or when the first instance of CVE-2026-76504 exploitation occurred. Federal Civilian Executive Branch (FCEB) agencies have time until October 3, 2026, to apply the fixes.

    Cybersecurity

    “Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone — this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” Jake Knott, head of threat intelligence at watchTowr, said in a statement.

    “None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target.”

    Organizations running Catalyst SD-WAN Manager are advised to upgrade to a fixed release as soon as possible and follow vendor guidance to hunt for POST requests to any URL-encoded variants of “/j_security_check” and review instances for signs of exploitation.

    adds auth Bypass catalyst CISA Cisco Exploited KEV manager SDWAN
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

    GitLab warns of critical RCE vulnerability in AI Gateway service

    Warlock ransomware breach SharePoint in water, telecom operator attacks

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    October 3, 2026

    Cboe wants to turn VIX into a never-ending trade: Crypto Daily

    October 3, 2026

    ‘Nature-Based’ Solutions Could Save Insurers and Policyholders Billions

    October 3, 2026

    What do Britain’s death-penalty cheerleaders have to say about Christa Pike? | Maya Foa

    October 3, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    October 3, 2026

    Cboe wants to turn VIX into a never-ending trade: Crypto Daily

    October 3, 2026

    ‘Nature-Based’ Solutions Could Save Insurers and Policyholders Billions

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.