Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on Lula v the Bolsonaros: the decision of Brazilian voters will affect us all | Editorial

    September 30, 2026

    US immigration judge allows cold war-era law to deport Wisconsin mosque’s president | Wisconsin

    September 30, 2026

    UK-France ‘one in, one out’ migrant scheme scrapped

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on Lula v the Bolsonaros: the decision of Brazilian voters will affect us all | Editorial
    • US immigration judge allows cold war-era law to deport Wisconsin mosque’s president | Wisconsin
    • UK-France ‘one in, one out’ migrant scheme scrapped
    • The Guardian view on falling pupil numbers: a chance to improve opportunities for young people | Editorial
    • Interview with La Croix
    • Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
    • Cisco warns of new SD-WAN zero-day exploited in attacks
    • Petrobras Tests Cardano for Renewable Fuel Traceability
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco warns of new SD-WAN zero-day exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.

    Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.

    “In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,” the company warned on Wednesday. “Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.”

    The CVE-2026-76504 vulnerability affects all deployments regardless of system configuration, was found in API session-based authentication management, and allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.

    “This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint,” Cisco added.

    “An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system.”

    While the company didn’t share further details regarding attacks exploiting CVE-2026-76504, it shared indicators of compromise (IOCs) warning admins that threat actors are using %6a as the URI-encoded character “j” in malicious requests.

    It also advised security teams investigating potentially compromised SD-WAN systems to check the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/for entries related to j_security_check from unknown or unauthorized IP addresses.

    “For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC,” it added, advising admins first to collect admin-tech files to support the review.









    Cisco Catalyst SD-WAN Release First Fixed Release
    Earlier than 20.9 Migrate to a fixed release.
    20.9 20.9.10.1
    20.12 20.12.8.2
    20.15 20.15.6.1
    20.18 20.18.4.1
    26.1 26.1.2.1
    26.2 26.2.1

    Fifth actively exploited SD-WAN zero-day in 2026

    CVE-2026-76504 is the fifth SD-WAN zero-day vulnerability actively exploited in the wild since the start of the year.

    Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127) in February, exploited since at least 2023, and tagged a maximum-severity Catalyst SD-WAN Controller auth bypass flaw (CVE-2026-20182) as actively exploited in zero-day attacks to gain admin privileges on unpatched devices in May.

    More recently, in early June, Cisco warned of two more SD-WAN zero-days (CVE-2026-20245 and CVE-2026-20262) that attackers exploited to gain root privileges on vulnerable systems.

    Since November 2021, the Cybersecurity and Infrastructure Security Agency (CISA) has tagged 90 Cisco vulnerabilities as exploited in the wild, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks Cisco Exploited SDWAN warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    The MFA you have isn’t the MFA you think you have

    Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    TeamViewer urges users to patch severe flaws “as soon as possible”

    AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

    Bitget hacked via zero-day in third-party security products

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on Lula v the Bolsonaros: the decision of Brazilian voters will affect us all | Editorial

    September 30, 2026

    US immigration judge allows cold war-era law to deport Wisconsin mosque’s president | Wisconsin

    September 30, 2026

    UK-France ‘one in, one out’ migrant scheme scrapped

    September 30, 2026

    The Guardian view on falling pupil numbers: a chance to improve opportunities for young people | Editorial

    September 30, 2026
    Latest Posts

    Don Lemon Accuses Justice Dept. of Vindictive Prosecution in Church Protest Case

    August 7, 2026

    Kemi Badenoch pens letter to Clacton voters ahead of by-election

    August 7, 2026

    Thetford residents remain on edge after days of ‘mob rule’ over asylum plans | Norfolk

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on Lula v the Bolsonaros: the decision of Brazilian voters will affect us all | Editorial

    September 30, 2026

    US immigration judge allows cold war-era law to deport Wisconsin mosque’s president | Wisconsin

    September 30, 2026

    UK-France ‘one in, one out’ migrant scheme scrapped

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.