A new critical vulnerability has been discovered in Cisco’s Catalyst SD-WAN Manager, a network management software used to monitor and manage up to 6,000 Software-Defined Wide Area Network (SD-WAN) devices. The flaw, tracked as CVE-2026-76504, allows unauthenticated attackers to access vulnerable systems remotely with administrator privileges, marking the fifth SD-WAN zero-day vulnerability exploited in the wild this year.
The Catalyst SD-WAN Manager is a crucial component of many organizations’ network infrastructure, providing a single dashboard for administrators to monitor and manage their SD-WAN devices. However, a vulnerability in the software’s API session-based authentication management allows attackers to bypass security rules and gain unauthorized access to sensitive systems.
According to Cisco, the CVE-2026-76504 vulnerability is due to improper handling of URI encoding in HTTP requests, which enables attackers to send malicious requests to vulnerable systems. The company has released security updates to address the issue, urging customers to upgrade to a fixed software release as soon as possible. In fact, Cisco warns that “customers who do not take this action may be at risk of exploitation” by threat actors using the vulnerability.
The discovery of CVE-2026-76504 is particularly concerning given its severity and widespread impact. The vulnerability affects all deployments, regardless of system configuration, making it a critical issue for organizations relying on Cisco’s SD-WAN Manager. Furthermore, the fact that attackers are actively exploiting this zero-day vulnerability highlights the need for prompt action to prevent potential data breaches.
To mitigate the risk of exploitation, security teams are advised to investigate potentially compromised systems by checking the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/ for entries related to j_security_check from unknown or unauthorized IP addresses. Cisco has also shared indicators of compromise (IOCs) warning admins that threat actors are using %6a as the URI-encoded character “j” in malicious requests.
In light of this new vulnerability, organizations relying on Cisco’s SD-WAN Manager must prioritize patching and upgrading their systems to the latest fixed release. This is not a one-time task but an ongoing process to ensure the security and integrity of their network infrastructure. With the increasing number of zero-day vulnerabilities being exploited in the wild, it has never been more crucial for organizations to stay vigilant and proactive in addressing potential security threats.
As a takeaway, we recommend that IT administrators and security teams prioritize patching and upgrading their SD-WAN Manager systems as soon as possible to prevent potential exploitation. Furthermore, regular monitoring of system logs and network activity is essential to detect any signs of malicious activity. By staying informed and taking proactive measures, organizations can reduce the risk of data breaches and ensure the continued security of their network infrastructure.
Source: Bleeping Computer — 2026-09-30