Cisco SD-WAN Zero-Day Under Active Exploitation Prompts Emergency CISA Directive
For the fifth time in 2026, Cisco has disclosed that attackers exploited a vulnerability in its SD-WAN product line before a patch was available. CVE-2026-76504, rated 9.8 on the CVSS scale, affects the session authentication mechanism in Cisco Catalyst SD-WAN Manager and allows remote, unauthenticated attackers to gain administrator-level access to the system's API.
The vulnerability stems from improper handling of URI encoding in HTTP requests. An attacker can craft a request that bypasses an authentication rule designed to restrict access to a specific API endpoint. Cisco's incident response team discovered the exploitation in September 2026 after investigating a technical support case. There are no workarounds — the only mitigation is applying the security update.
The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalogue and ordered federal civilian agencies to address it by October 3, 2026, an unusually tight three-day deadline. Rapid7 has separately urged organisations to audit affected systems for signs of compromise, noting that any SD-WAN Manager instance with ports exposed to the internet is potentially at risk.
Affected releases span versions 20.9 through 26.2 and all earlier versions. Organisations running anything older than version 20.9.10.1 must migrate to a fixed release. The repeated pattern of SD-WAN zero-days throughout 2026 raises questions about the architectural attack surface of network management platforms that remain internet-accessible in many enterprise deployments.
Source: Help Net Security. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.