Protect.Computer
NEWS

Cisco Patches Fifth SD-WAN Zero-Day of 2026, Under Attack

· 1 min read · Network safety Got hacked
Cisco Patches Fifth SD-WAN Zero-Day of 2026, Under Attack

Cisco has released fixes for CVE-2026-76504, a critical zero-day in Catalyst SD-WAN Manager (formerly vManage), the dashboard admins use to manage up to 6,000 SD-WAN devices. Cisco’s PSIRT says it became aware of active exploitation in September 2026. The flaw sits in API session authentication: improper handling of URI encoding lets a crafted HTTP request slip past an authentication rule meant to protect a specific API endpoint, giving an unauthenticated remote attacker admin privileges. It affects all deployments regardless of configuration.

Cisco shared few details on the attacks but published indicators: malicious requests use %6a as the URL-encoded letter “j”. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, with a federal deadline of Saturday, October 3. BleepingComputer counts this as the fifth actively exploited SD-WAN zero-day this year, following CVE-2026-20127 (February), CVE-2026-20182 (May), and CVE-2026-20245 and CVE-2026-20262 (June).

How to check if you’re affected

Affected products are all Cisco Catalyst SD-WAN Manager deployments on versions earlier than the first fixed release for their train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Releases earlier than 20.9 have no fix and must migrate to a fixed release. To look for compromise, search /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check entries from unknown IP addresses, and watch for requests containing %6a. Collect admin-tech files before opening a Cisco TAC case, and restrict management interface access to trusted networks while you patch.

Sources

Related reading