hacker-news · Crawled Oct 1, 2026

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

3 IoCs
Read original article ↗

AI Summary

Cisco has confirmed active exploitation of a critical zero-day authentication bypass vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager. The flaw allows unauthenticated remote attackers to bypass authentication and access the system's API as an admin user by exploiting improper URI encoding handling in HTTP requests. The vulnerability affects all on-premises SD-WAN Manager installations regardless of configuration, with a CVSS score of 9.8, and no workaround exists other than applying fixed software releases. Cisco advises customers to restrict internet access to the Manager and check specific log files for signs of compromise involving URI-encoded paths like /%6a_security_check.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Filename j_security_check Details →
Filename /var/log/nms/containers/service-proxy/serviceproxy-access.log Details →
Filename /var/log/nms/vmanage-server.log Details →