The news
Cisco Systems (CSCO) disclosed on September 30, 2026, that attackers had exploited a Cisco SD-WAN zero-day, CVE-2026-76504, which lets an unauthenticated remote attacker reach the Catalyst SD-WAN Manager API as the admin user. Patched software is out, and Cisco says no workaround exists.
Catalyst SD-WAN Manager, formerly called vManage, is the central console companies use to configure and monitor a software-defined wide area network (SD-WAN), the routers and links that connect offices, data centers and cloud services. Cisco's advisory rates the flaw 9.8 out of 10 on the Common Vulnerability Scoring System and says it affects the product regardless of configuration.
According to the advisory, the bug comes from improper handling of URI encoding in an HTTP request. A crafted request can bypass authentication. A zero-day is a flaw attackers use before a fix exists. Cisco said its Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026, and that the issue surfaced while its Technical Assistance Center was working a customer support case.
The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on September 30. SecurityWeek and The Hacker News reported that federal civilian agencies were given until October 3 to fix it. The Hacker News reported that Cisco has not said who is behind the attacks or how many organizations were hit.
The first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Cisco says there are no workarounds, though it recommends restricting internet access to the manager and keeping it behind a firewall. The advisory says cloud-hosted environments already have those protections in place.
Cisco also published signs of compromise. Administrators should search the serviceproxy-access.log and vmanage-server.log files for POST requests to j_security_check that contain URI-encoded characters, such as %6a, from unfamiliar IP addresses. BleepingComputer noted that %6a is the encoded form of the letter j.
The numbers
- CVSS severity score
- 9.8 of 10 (Critical)
- Disclosed and added to CISA's exploited list
- September 30, 2026
- Federal civilian agency fix deadline
- October 3, 2026
- Earlier Cisco SD-WAN zero-days in 2026 (BleepingComputer count)
- 4
- 2026 Cisco SD-WAN CVEs on CISA's list (watchTowr count)
- 8
Why CEOs should care
For CISOs, the sequence matters more than the score. Cisco learned of attacks in September and published fixes on September 30, so any internet-reachable manager may have been exposed before a patch existed. Patching closes the door but does not show whether someone already walked through it. Run Cisco's log checks, and if they turn up hits, treat it as an incident: review admin accounts, recent configuration and policy changes, and any new tunnels or routes pushed to branch devices.
For CIOs and IT buyers, ask a simple question: can our SD-WAN Manager be reached from the internet, and why? Cisco's own mitigation advice is to restrict that access. Many companies run SD-WAN through a carrier or managed service provider, so get written confirmation of the patched version and the log review rather than assuming it happened. Contracts should spell out how fast a provider applies critical fixes.
For boards and CFOs, the pattern is the risk. BleepingComputer counted four earlier Cisco SD-WAN zero-days in 2026: CVE-2026-20127 in February, CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June. Repeated emergency patching costs staff time and raises the odds of a missed window. That history belongs in renewal talks and in the next review of network vendor risk.
The bigger picture
Management consoles and edge devices have become favored targets because one foothold can reach many systems. Jake Knott, head of threat intelligence at security firm watchTowr, said in comments quoted by The Hacker News that eight 2026 Cisco SD-WAN CVEs have landed on CISA's list, calling it a clear signal that attackers value the platform. He said the pattern is unlikely to slow down. For defenders, that argues for putting SD-WAN Manager on the short list of systems that get emergency patching and continuous log monitoring, alongside other internet-facing gear.
What’s next
Cisco updated its advisory on October 2, and further revisions may add detail on the attacks or the attackers. Watch for any CISA guidance beyond the October 3 federal deadline, for threat intelligence firms naming the group involved, and for customer disclosures if log reviews turn up earlier compromises.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








