hacker-news · Crawled Oct 1, 2026

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

2 IoCs
Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation observed in the wild. The flaw, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to bypass authentication by sending a crafted HTTP request to the API, gaining admin-level access. Organizations are urged to apply patches immediately and review specific log files for signs of compromise, including suspicious POST requests to URL-encoded variants of '/j_security_check' and activity involving user accounts starting with 'viptela-reserved-'.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename serviceproxy-access.log Details →
Filename vmanage-server.log Details →