Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Cisco Warns of Critical Zero-Day Flaw in SD-WAN Manager, Advises Immediate Upgrade




Cisco has issued a critical warning to its customers regarding a zero-day flaw in its SD-WAN Manager, which carries a CVSS score of 9.8 out of 10. The vulnerability allows a remote attacker to bypass authentication rules and gain unauthorized access to the system. Cisco advises its customers to upgrade to a fixed release immediately to avoid potential security breaches.

  • Cisco has issued a warning about a critical zero-day flaw in its SD-WAN Manager, with a CVSS score of 9.8 out of 10.
  • The vulnerability, CVE-2026-76504, allows a remote attacker with no login access to bypass authentication rules.
  • The flaw is attributed to a mishandling of URI encoding in an HTTP request, making it easily exploitable.
  • Cisco advises immediate upgrade to a fixed release and recommends mitigating risk by restricting access to the Manager.
  • Customers should check for signs of compromise and report potential issues to Cisco TAC.



  • In a stark warning to network administrators and security professionals worldwide, Cisco has recently alerted its customers to a critical zero-day flaw in its SD-WAN Manager, a system used to manage and secure Cisco SD-WAN networks. The vulnerability, identified as CVE-2026-76504, carries a CVSS score of 9.8 out of 10, indicating a high level of severity and risk.

    According to Cisco's Product Security Incident Response Team, the flaw was discovered in September 2026, while the team was handling a support case. The vulnerability allows a remote attacker with no login access to use the Manager's API as the admin user, effectively bypassing authentication rules intended to restrict access to a single API endpoint. This means that even an attacker with no credentials can exploit the flaw to gain unauthorized access to the system.

    The vulnerability is attributed to a mishandling of URI encoding in an HTTP request, which allows a crafted request to bypass the authentication rule. The attacker needs only the ability to send the request to the Manager's API to exploit the flaw. In addition, the admin user holds the netadmin role, which is allowed to perform all operations on the device, making it even easier for an attacker to gain access.

    Cisco has advised its customers to upgrade to a fixed release immediately, as there is no workaround for the vulnerability. The first fixed releases for each release train have been made available, and customers are advised to migrate to a fixed release to avoid potential security breaches.

    In light of this critical alert, network administrators and security professionals are advised to take immediate action to secure their SD-WAN networks. The advisory includes recommendations for mitigating the risk of compromise, such as restricting access to the Manager from unsecured networks, allowing only known, trusted hosts to access the system, and implementing HTTPS access only from a jump host or a management subnet.

    Furthermore, customers are advised to check for signs of compromise, such as j_security_check entries in the service-proxy-access.log and vmanage-server.log files, which are potential indicators of a compromised system. The advisory also includes a procedure for opening a Severity 3 case with Cisco TAC and including CVE-2026-76504 in the title to help determine whether a Manager has been compromised.

    As the first in a series of critical vulnerabilities in Cisco SD-WAN products, this alert serves as a reminder to network administrators and security professionals to remain vigilant and proactive in securing their networks against the latest threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Cisco-Warns-of-Critical-Zero-Day-Flaw-in-SD-WAN-Manager-Advises-Immediate-Upgrade-ehn.shtml

  • https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-76504

  • https://www.cvedetails.com/cve/CVE-2026-76504/


  • Published: Wed Sep 30 11:49:43 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us