Cisco SD-WAN Zero-Day Exploited: Unauthenticated Admin Access Poses Critical Threat to Federal Agencies
A critical authentication bypass vulnerability, identified as CVE-2026-76504, is currently under active exploitation against Cisco Catalyst SD-WAN Manager. This flaw, rated with a CVSS score of 9.8, enables unauthenticated remote attackers to gain administrative access to the management API. The root cause lies in the improper handling of URL/URI encoding, specifically within the `j_security_check` path. By simply substituting the character 'j' with its URI-encoded equivalent, `%6a`, an attacker can circumvent the authentication rules protecting the management API, effectively tricking the system into granting access without valid credentials.
This incident is particularly significant because the SD-WAN Manager serves as a centralized control point for a vast number of devices, potentially up to 6,000. Compromising a single instance can therefore provide an attacker with widespread control over a large-scale network infrastructure. Cisco PSIRT confirmed active exploitation of this vulnerability in September 2026, and the Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Federal agencies have been given a strict mandate to remediate this vulnerability by October 3, 2026, underscoring the severe threat it poses to critical infrastructure.
This incident is not isolated; it marks the fifth actively exploited SD-WAN zero-day vulnerability in 2026 alone, indicating a persistent and growing vulnerability in the management layer of software-defined networking. Since November 2021, CISA has cataloged 90 Cisco vulnerabilities that have been exploited in the wild, with seven of these being leveraged by ransomware operations. This trend highlights a critical need for organizations to move beyond reactive patching and implement more robust, proactive security testing for all management-facing APIs before deployment. The cumulative impact of these exploited vulnerabilities suggests that current security models are insufficient. While immediate application of fixed releases for CVE-2026-76504 is crucial, the long-term challenge lies in addressing the systemic issue of over-reliance on default trust mechanisms that continue to facilitate these high-impact breaches. For private sector entities, the risk is equally acute, demanding a re-evaluation of their security postures and incident response strategies to account for such sophisticated and easily exploitable flaws. The lack of readily available workarounds further emphasizes the urgency of applying the official patches.
Read original source