bleeping-computer · Crawled Oct 1, 2026

Cisco warns of new SD-WAN zero-day exploited in attacks

1 IoCs
Read original article ↗

AI Summary

Cisco has warned of active exploitation of a critical zero-day vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager (formerly vManage) software. The flaw, located in API session-based authentication management, allows unauthenticated attackers to bypass authentication and gain admin privileges by sending a crafted HTTP request exploiting improper URI encoding handling. Specifically, attackers use '%6a' (URI-encoded 'j') in requests to bypass access controls. Cisco urges customers to apply fixed software releases immediately, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 3, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain %6a Details →