Cisco warns of new SD-WAN zero-day exploited in attacks

A Critical Zero-Day Exploit Puts SD-WAN Networks at Risk

Cisco has issued a critical security update to address a zero-day vulnerability in its Catalyst SD-WAN Manager software. Attackers are actively exploiting this flaw to gain admin privileges on vulnerable systems, and Cisco is urging customers to upgrade to the latest fixed release as soon as possible.

The affected software, formerly known as SD-WAN vManage, allows administrators to monitor and manage up to 6,000 SD-WAN devices from a single dashboard. However, an attacker can exploit this vulnerability by sending a specially crafted HTTP request to the API of the affected system. This flaw lies in the way the software handles URI encoding in HTTP requests, allowing malicious actors to bypass authentication rules and gain access with admin privileges.

What’s concerning is that this isn’t just any ordinary vulnerability – it’s a zero-day exploit, meaning attackers are already actively using it in the wild. Cisco has warned that all deployments of the Catalyst SD-WAN Manager are affected, regardless of their configuration, making this a high-risk issue for organizations relying on the software.

Cisco recommends that customers upgrade to the latest fixed release as soon as possible to remediate the vulnerability. The company also shared indicators of compromise (IOCs) to help administrators identify potential attacks. Specifically, it warned about the use of the URI-encoded character “%6a” in malicious requests. Administrators should be on high alert and check their system logs for signs of unauthorized access.

This is the fifth SD-WAN zero-day vulnerability that has been actively exploited since the start of this year alone. It’s a stark reminder of the importance of keeping software up-to-date, especially when it comes to critical infrastructure like network management systems. Cisco has already patched several vulnerabilities in its SD-WAN Manager software, but this latest exploit highlights the ongoing risk posed by these types of attacks.

In related news, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76504 to its Known Exploited Vulnerabilities Catalog and ordered U.S. federal agencies to secure their systems against attacks by Saturday, October 3.

To protect your organization from this type of attack, we recommend taking immediate action: review your SD-WAN software versions, apply the latest security patches, and conduct regular vulnerability scans to identify potential weaknesses. In today’s threat landscape, staying one step ahead of attackers requires a proactive approach to cybersecurity.


Source: Bleeping Computer — 2026-09-30