Cisco Warns of Critical SD-WAN Zero-Day Exploited in Wild
Cisco has issued an emergency warning about a critical zero-day vulnerability in its Catalyst SD-WAN Manager product. The bug, CVE-2026-76504, allows attackers to bypass authentication and access sensitive endpoints with administrator privileges.
The company became aware of active exploitation in September 2026 and released fixed software the same week it published the advisory. Cisco recommends that customers upgrade to a fixed release to remediate the vulnerability, as there is no workaround available.
The bug affects all Catalyst SD-WAN Manager deployments, regardless of configuration, and can be exploited by sending a crafted HTTP request to the API with no credentials or user interaction required. The National Vulnerability Database rates the CVSS score at 9.8 out of 10 due to its high severity.
Cisco has shared indicators of compromise, including the use of the URI-encoded sequence %6a in malicious requests aimed at the vulnerable endpoint. Security teams are advised to search log files for entries tied to j_security_check that originate from unknown or unauthorized IP addresses.