Cisco SD-WAN Manager hit by zero-day admin access attack
Summary
Cisco's SD-WAN Manager software is vulnerable to a zero-day attack that allows attackers to gain administrative access by bypassing authentication checks through improper handling of URI encoding in HTTP requests. The vulnerability, tracked as CVE-2026-76504, has a critical CVSS score of 9.8 and can be exploited remotely without credentials or user interaction. Cisco has released patches for affected versions, and customers are advised to upgrade and restrict access to the management interface from unsecured networks.
IFF Assessment
The discovery of a critical zero-day vulnerability that grants administrative access to network management software is bad news for defenders as it presents a significant risk to infrastructure.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: October 03, 2026. Known ransomware use: Unknown.
Defender Context
This critical vulnerability in Cisco SD-WAN Manager highlights the significant risk posed by vulnerabilities in network management planes. Defenders must prioritize patching this issue and segmenting their management interfaces to mitigate the impact of such exploits. The ease of exploitation and high privileges gained make this a prime target for attackers seeking to disrupt or control network infrastructure.