Summary
Cisco released security updates for a zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that attackers are actively exploiting to gain admin privileges. The flaw allows unauthenticated remote access to the management API through URI encoding bypasses.
Take Action:
If you run Cisco Catalyst SD-WAN Manager, make sure it is isolated from the internet and reachable from trusted networks only, then patch it ASAP to the fixed version for your release (or migrate if you're on anything older than 20.9). Before patching, save an admin-tech file and check the logs for suspicious j_security_check requests or activity from viptela-reserved- accounts. If you find any, assume your whole SD-WAN network is compromised and call in incident response.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)