Cisco SD-WAN Zero-Day (CVE-2026-76504) Exploited in Wild

Cisco Patches Actively Exploited SD-WAN Auth Bypass Zero-Day

CRITICAL
October 1, 2026
5m read
VulnerabilityPatch ManagementCyberattack

CVE Identifiers

CVE-2026-76504
CRITICAL
CVSS:9.8

Full Report

Executive Summary

Cisco has released an emergency security advisory for a critical, actively exploited zero-day vulnerability in its Cisco Catalyst SD-WAN Manager. The vulnerability, tracked as CVE-2026-76504, is an authentication bypass flaw with a CVSS score of 9.8 (Critical). It allows an unauthenticated, remote attacker to gain administrative privileges on an affected system by sending a crafted HTTP request. Cisco's Product Security Incident Response Team (PSIRT) confirmed active exploitation in the wild. In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch. There are no workarounds, and all organizations are urged to apply the available software updates immediately.


Vulnerability Details

CVE-2026-76504 stems from the improper handling of URI encoding in HTTP requests sent to the API of a Cisco Catalyst SD-WAN Manager instance. An attacker can craft a specific HTTP request with manipulated URI encoding to bypass the system's authentication and authorization checks.

A successful exploit grants the attacker the same privileges as the admin user, which by default provides complete control over the SD-WAN fabric. This includes the ability to view, modify, or delete configurations, monitor traffic, and potentially pivot to other network devices managed by the SD-WAN Manager.

  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None

Affected Systems

The vulnerability affects the following releases of Cisco Catalyst SD-WAN Manager:

  • 20.9 and earlier
  • 20.12 and earlier
  • 20.15 and earlier
  • 20.18 and earlier
  • 26.1 and earlier
  • 26.2 and earlier

Any organization utilizing these versions, especially if the management interface is exposed to the internet, is at immediate risk of compromise.

Exploitation Status

Cisco PSIRT discovered the exploitation while investigating a customer support case in September 2026. The active, in-the-wild exploitation demonstrates that threat actors have developed a reliable method to leverage this flaw. The low complexity of the exploit means that once technical details are widely disseminated, a significant increase in attacks from various actors is highly probable. CISA's inclusion of CVE-2026-76504 in the KEV catalog on September 30, 2026, reinforces the severity and active threat posed by this vulnerability.

Impact Assessment

The impact of a successful exploit is severe. Gaining administrative control over the Catalyst SD-WAN Manager effectively gives an attacker the "keys to the kingdom" for an organization's wide area network. An attacker could:

  • Re-route traffic for man-in-the-middle attacks or eavesdropping.
  • Disrupt network operations, causing widespread outages.
  • Weaken security policies across the entire SD-WAN fabric.
  • Use the manager as a launchpad to attack other connected branch offices and data centers.

For any organization reliant on its WAN for business operations, a compromise of the central management plane represents a critical business continuity and security risk.


Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to identify potential exploitation attempts:

Type
URL Pattern
Value
Malformed or unusually encoded URI paths in requests to the SD-WAN Manager API.
Description
Look for requests containing characters like %2e for dot, %2f for slash, or other non-standard encoding in web server logs.
Type
Log Source
Value
Web server access logs on the Catalyst SD-WAN Manager.
Description
Hunt for HTTP requests to the API endpoint that result in a 200 OK status from an unauthenticated or unknown source IP.
Type
Event ID
Value
Unauthorized configuration change alerts.
Description
Any configuration changes originating from an unknown IP address or occurring outside of normal change windows should be investigated.

Detection & Response

Organizations should focus on identifying signs of compromise and ensuring a swift response.

  1. Web Log Analysis: D3-WSAA: Web Session Activity Analysis. Scrutinize web access logs for the Catalyst SD-WAN Manager. Look for suspicious HTTP requests, particularly those with unusual URI encoding patterns targeting the API. Correlate successful API access from untrusted IP addresses with the vulnerability's discovery timeline.
  2. Audit Configuration Changes: Review all configuration changes within the SD-WAN Manager. Investigate any unauthorized or unexpected modifications to routing policies, security settings, or device configurations. An attacker with admin access would likely alter configurations to establish persistence or redirect traffic.
  3. User Account Review: D3-LAM: Local Account Monitoring. Examine the SD-WAN Manager for any newly created administrative accounts or modifications to existing accounts. Attackers often create their own accounts for persistent access.

Remediation Steps

There are no workarounds for this vulnerability. Patching is mandatory.

  1. Apply Updates: D3-SU: Software Update. Immediately upgrade all Cisco Catalyst SD-WAN Manager instances to a fixed software release as detailed in the Cisco security advisory.
  2. Restrict Access: As a best practice and compensating control, ensure the management interface of the Catalyst SD-WAN Manager is not exposed to the public internet. Access should be restricted to a secure, internal management network and controlled via strict firewall rules.
  3. Assume Compromise: For any internet-exposed managers, organizations should assume they have been compromised. After patching, conduct a thorough audit of all configurations, user accounts, and logs to identify and remediate any malicious changes made by attackers.

Timeline of Events

1
September 30, 2026
Cisco releases a security advisory for CVE-2026-76504 after discovering active exploitation.
2
September 30, 2026
CISA adds CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) Catalog.
3
October 1, 2026
This article was published

MITRE ATT&CK Mitigations

Applying the vendor patch is the only way to remediate this vulnerability. There are no workarounds.

Mapped D3FEND Techniques:

Restricting network access to the management interface of the SD-WAN Manager significantly reduces the attack surface.

Mapped D3FEND Techniques:

Regularly auditing configuration changes and administrative logins can help detect unauthorized activity resulting from a compromise.

D3FEND Defensive Countermeasures

Given the critical severity, active exploitation, and lack of workarounds, the immediate application of Cisco's provided software updates is mandatory. Organizations must identify all vulnerable Cisco Catalyst SD-WAN Manager instances within their environment. The patching process should be treated as an emergency change, prioritizing any internet-facing managers first. After applying the update, administrators must verify the new software version is correctly installed and the system is no longer vulnerable. This action is the only definitive way to prevent exploitation of CVE-2026-76504.

As a critical compensating control, organizations must implement strict inbound traffic filtering for their Cisco Catalyst SD-WAN Manager interfaces. The management plane should never be exposed directly to the public internet. Access should be restricted via firewall rules to a small, well-defined set of trusted IP addresses, such as corporate VPNs or dedicated administrative jump hosts. This practice of network hardening dramatically reduces the attack surface, making it significantly harder for a remote, unauthenticated attacker to even reach the vulnerable API endpoint. This control should be implemented immediately, even before patching is complete, to provide an initial layer of defense.

In the context of the SD-WAN Manager, this translates to rigorous monitoring of all administrative accounts and system configurations. Security teams should assume that any internet-facing, unpatched systems have been compromised. A thorough audit of all user accounts, especially those with 'admin' privileges, is necessary to identify any unauthorized accounts created by attackers. Furthermore, all system and network configurations should be reviewed against a known-good baseline to detect malicious modifications, such as altered routing policies or new firewall rules designed to facilitate further attacks. Alerts should be configured for any administrative login from an unrecognized IP or any configuration change made outside of a standard maintenance window.

Timeline of Events

1
September 30, 2026

Cisco releases a security advisory for CVE-2026-76504 after discovering active exploitation.

2
September 30, 2026

CISA adds CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) Catalog.

Sources & References

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
Infosecurity Magazine (infosecurity-magazine.com) •October 1, 2026
New Cisco SD-WAN zero-day exploited in the wild (CVE-2026-76504)
Help Net Security (helpnetsecurity.com) •October 1, 2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA (cisa.gov) •September 30, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

zero-dayauthentication bypassRCESD-WANKEVCisco

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.