Cisco says attackers exploit critical SD-WAN flaw
Cisco says attackers are actively exploiting a critical authentication bypass in Catalyst SD-WAN Manager, a network-management product, and has released software updates to fix the flaw. The vulnerability, tracked as CVE-2026-76504, could let an unauthenticated remote attacker access the Manager API with administrator privileges. Cisco rates it 9.8 out of 10 in severity and says it affects the product regardless of system configuration. Cisco said its Product Security Incident Response Team became aware of the active exploitation in September 2026. The company has not disclosed who is carrying out the attacks, how many customers or systems have been affected, when the attacks began, or what attackers may have done after gaining access. The flaw stems from improper handling of URI encoding in HTTP requests to the API’s session-based authentication component. A specially crafted request can bypass an authentication rule meant to restrict access to a particular endpoint, Cisco said. The company’s example encodes a character in the j_security_check path, but Cisco cautions that the example is not the only possible variation.