Cisco SD-WAN Zero-Day Exploited in the Wild
Cisco has patched a zero-day vulnerability in its SD-WAN Manager networking software. The flaw, filed under CVE-2026-76504, allows remote hackers to bypass authentication and gain administrator-level access.
The bug is located in the API session-based authentication management layer and was discovered during a customer support case. It has been given a severity score of 9.8 out of 10 and is one of 17 Cisco vulnerabilities that have been recorded as exploited this year, up from eight in 2025 and six in 2024.
Cisco has published indicators of compromise (IOCs) for defenders to use in checking for signs of attack. Customers are advised to audit the serviceproxy-access.log file for entries related to j_security_check from unknown or unauthorized IP addresses.