Cisco SD-WAN Manager hit by zero-day admin access attack

Summary

Cisco's SD-WAN Manager software is vulnerable to a zero-day attack that allows attackers to gain administrative access by bypassing authentication checks through improper handling of URI encoding in HTTP requests. The vulnerability, tracked as CVE-2026-76504, has a critical CVSS score of 9.8 and can be exploited remotely without credentials or user interaction. Cisco has released patches for affected versions, and customers are advised to upgrade and restrict access to the management interface from unsecured networks.

IFF Assessment

FOE

The discovery of a critical zero-day vulnerability that grants administrative access to network management software is bad news for defenders as it presents a significant risk to infrastructure.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: October 03, 2026. Known ransomware use: Unknown.

Defender Context

This critical vulnerability in Cisco SD-WAN Manager highlights the significant risk posed by vulnerabilities in network management planes. Defenders must prioritize patching this issue and segmenting their management interfaces to mitigate the impact of such exploits. The ease of exploitation and high privileges gained make this a prime target for attackers seeking to disrupt or control network infrastructure.

Read Full Story →