Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

The Hacker News by The Hacker News
September 30, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalSep 30, 2026Vulnerability / Network Security

Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.

The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager’s API as the admin user. Fixed releases are available, and there is no workaround. It carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager’s API that handles login sessions.

The Manager mishandles URI encoding in an HTTP request. A crafted request can therefore bypass an authentication rule intended to restrict access to a single API endpoint.

The attacker needs no credentials, only the ability to send that request to the Manager’s API. Managers exposed to the internet are at risk of compromise, according to Cisco. By default, the admin user holds the netadmin role, which is allowed to perform all operations on the device.

Cisco said its Product Security Incident Response Team “became aware of active exploitation of this vulnerability” in September 2026. The flaw was found while Cisco’s Technical Assistance Center (TAC) was handling a support case.

The advisory does not say how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access.

Who Needs to Upgrade

The flaw affects SD-WAN Manager regardless of how the system is configured. No other product is listed as affected. These are the first fixed releases for each release train:

Release train First fixed release
Earlier than 20.9 Migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier: CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June.

A comparison of the advisories shows that the fixed releases for those flaws are all older than the ones in the table above. So a Manager last upgraded for the May or June fixes still needs this update.

The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco’s May advisory did list. The advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), two deployment types named in the May and June advisories.

Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action. Until an on-prem Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet. Where internet access is required, only known, trusted hosts should be allowed in, and the control components should sit behind a firewall.

Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place. The mitigation worked in a test environment, according to Cisco, which advises customers to assess its impact on their own networks before applying it.

Cisco’s SD-WAN hardening guide says administrative interfaces, such as ports 443, 22 and 830, should not be exposed directly to the internet. HTTPS access to the Manager should come only from a jump host or a management subnet.

Checking for Signs of Compromise

The signs of compromise Cisco describes involve j_security_check, the request path the Manager uses for session-based logins. In Cisco’s example, one character of that path is URI-encoded, giving /%6a_security_check, where %6a stands for the letter j.

Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses:

  • File: /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • File: /var/log/nms/vmanage-server.log, in particular entries for users whose names start with viptela-reserved-

Names starting with viptela-reserved- belong to reserved system service accounts.

Any one character in the request can be encoded, so %6a is only an example. The same entries can also appear during normal operation, and each match has to be checked against normal activity to avoid false positives.

To help determine whether a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title. Cisco asks them to run request admin-tech on the Manager first, so the output file can be reviewed.

The advisory includes no detection rule and does not say whether upgrading removes an attacker who already has access. Cisco’s advisories for the May flaw and the first June flaw said an update alone would not resolve a confirmed compromise. They told customers to collect the admin-tech file before upgrading.

CVE-2026-76504 follows a series of Cisco SD-WAN flaws flagged as exploited this year. As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026.



Source link

The Hacker News

The Hacker News

Next Post

Accenture Cyber Exec: Industry Is Moving Beyond ‘Whack-A-Mole’ Patching Amid AI-Driven Vulnerability Surge

Recommended.

Huawei prezentuje nową serię urządzeń ubieralnych w Berlinie, wkraczając w nową erę tej technologii

Huawei prezentuje nową serię urządzeń ubieralnych w Berlinie, wkraczając w nową erę tej technologii

May 17, 2025
Stocks making the biggest moves midday: Intel, Walgreens Boots Alliance, Nike, Super Micro Computer and more

Stocks making the biggest moves midday: Intel, Walgreens Boots Alliance, Nike, Super Micro Computer and more

February 18, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio