Cisco Fixes Exploited Zero-Day Vulnerability in Catalyst SD-WAN

www.news4hackers.com-cisco-fixes-exploited-zero-day-vulnerability-in-catalyst-sd-wan-cisco-fixes-exploited-zero-day-vulnerability-in-catalyst-sd-wan

Cisco issued urgent patches for a severe authentication bypass vulnerability impacting Catalyst SD-WAN Manager, which has been actively exploited in real-world scenarios.

Cisco Addressed a Critical Authentication Bypass Flaw

Cisco issued urgent patches on Wednesday for a severe authentication bypass vulnerability impacting Catalyst SD-WAN Manager, which has been actively exploited in real-world scenarios. The flaw, designated CVE-2026-76504 with a CVSS score of 9.8, affects the API session-based authentication mechanism, enabling remote, unauthenticated attackers to achieve administrative access to vulnerable systems.

Vulnerability Details

The Cisco Product Security Incident Response Team (PSIRT) became aware of the active exploitation in September 2026 and emphasized the necessity for customers to upgrade to a patched software release. The vulnerability arises from improper handling of URI encoding in HTTP requests, allowing malicious actors to bypass authentication controls and access restricted API endpoints. Exploitation involves crafting specific HTTP requests to target the affected system’s API, granting unauthorized administrative privileges.

Affected Systems and Patches

All deployments of Catalyst SD-WAN Manager are susceptible regardless of configuration, with no available workarounds. The issue was resolved in versions 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1, with Cisco-managed SD-WAN environments also receiving updates. Cisco provided indicators of compromise (IoCs) to assist security teams in detecting potential exploitation attempts and outlined recommendations for strengthening affected systems.

CISA’s Involvement

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included the vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches within three days. Neither Cisco nor CISA disclosed specifics about the exploitation in the wild. Industry analysts highlighted the recurring presence of Cisco SD-WAN vulnerabilities on CISA’s KEV list, noting eight 2026 CVEs added this year.

Industry Analysts’ Comments

Jake Knott, head of threat intelligence at WatchTowr, stated that the pattern underscores the platform’s attractiveness to attackers. He advised organizations to prioritize immediate upgrades and monitor for POST requests targeting URL-encoded variants of “/j_security_check,” while reviewing systems for signs of compromise.

Broader Cybersecurity Context

The advisory coincided with broader cybersecurity developments, including updates to Chrome and Firefox addressing over 100 vulnerabilities, and ongoing investigations into cybercriminal activities involving malware and zero-day exploits. Security professionals emphasized the urgency of mitigating the flaw, given its high severity and active exploitation.

Conclusion

Organizations using Catalyst SD-WAN Manager must act swiftly to apply the provided patches and implement monitoring strategies to mitigate risks associated with this critical vulnerability.



About Author

en_USEnglish