Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Cisco SD-WAN zero-day exploited to give attackers admin access; flaw rated 9.8

Cisco says attackers exploited a 9.8-rated flaw in Catalyst SD-WAN Manager that bypasses login and grants admin API access; patched releases are the only fix.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Cisco says CVE-2026-76504 lets an unauthenticated remote attacker reach the SD-WAN Manager API as the admin user.
  • 2Cisco's PSIRT learned of active exploitation in September 2026; CISA added the flaw to its exploited list on September 30.
  • 3There is no workaround: fixed releases run from 20.9.10.1 to 26.2.1, and Cisco published log checks for compromise.

The news

Cisco Systems (CSCO) disclosed on September 30, 2026, that attackers had exploited a Cisco SD-WAN zero-day, CVE-2026-76504, which lets an unauthenticated remote attacker reach the Catalyst SD-WAN Manager API as the admin user. Patched software is out, and Cisco says no workaround exists.

Catalyst SD-WAN Manager, formerly called vManage, is the central console companies use to configure and monitor a software-defined wide area network (SD-WAN), the routers and links that connect offices, data centers and cloud services. Cisco's advisory rates the flaw 9.8 out of 10 on the Common Vulnerability Scoring System and says it affects the product regardless of configuration.

According to the advisory, the bug comes from improper handling of URI encoding in an HTTP request. A crafted request can bypass authentication. A zero-day is a flaw attackers use before a fix exists. Cisco said its Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026, and that the issue surfaced while its Technical Assistance Center was working a customer support case.

The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on September 30. SecurityWeek and The Hacker News reported that federal civilian agencies were given until October 3 to fix it. The Hacker News reported that Cisco has not said who is behind the attacks or how many organizations were hit.

The first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Cisco says there are no workarounds, though it recommends restricting internet access to the manager and keeping it behind a firewall. The advisory says cloud-hosted environments already have those protections in place.

Cisco also published signs of compromise. Administrators should search the serviceproxy-access.log and vmanage-server.log files for POST requests to j_security_check that contain URI-encoded characters, such as %6a, from unfamiliar IP addresses. BleepingComputer noted that %6a is the encoded form of the letter j.

The numbers

CVSS severity score
9.8 of 10 (Critical)
Disclosed and added to CISA's exploited list
September 30, 2026
Federal civilian agency fix deadline
October 3, 2026
Earlier Cisco SD-WAN zero-days in 2026 (BleepingComputer count)
4
2026 Cisco SD-WAN CVEs on CISA's list (watchTowr count)
8

Why CEOs should care

For CISOs, the sequence matters more than the score. Cisco learned of attacks in September and published fixes on September 30, so any internet-reachable manager may have been exposed before a patch existed. Patching closes the door but does not show whether someone already walked through it. Run Cisco's log checks, and if they turn up hits, treat it as an incident: review admin accounts, recent configuration and policy changes, and any new tunnels or routes pushed to branch devices.

For CIOs and IT buyers, ask a simple question: can our SD-WAN Manager be reached from the internet, and why? Cisco's own mitigation advice is to restrict that access. Many companies run SD-WAN through a carrier or managed service provider, so get written confirmation of the patched version and the log review rather than assuming it happened. Contracts should spell out how fast a provider applies critical fixes.

For boards and CFOs, the pattern is the risk. BleepingComputer counted four earlier Cisco SD-WAN zero-days in 2026: CVE-2026-20127 in February, CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June. Repeated emergency patching costs staff time and raises the odds of a missed window. That history belongs in renewal talks and in the next review of network vendor risk.

The bigger picture

Management consoles and edge devices have become favored targets because one foothold can reach many systems. Jake Knott, head of threat intelligence at security firm watchTowr, said in comments quoted by The Hacker News that eight 2026 Cisco SD-WAN CVEs have landed on CISA's list, calling it a clear signal that attackers value the platform. He said the pattern is unlikely to slow down. For defenders, that argues for putting SD-WAN Manager on the short list of systems that get emergency patching and continuous log monitoring, alongside other internet-facing gear.

What’s next

Cisco updated its advisory on October 2, and further revisions may add detail on the attacks or the attackers. Watch for any CISA guidance beyond the October 3 federal deadline, for threat intelligence firms naming the group involved, and for customer disclosures if log reviews turn up earlier compromises.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CiscoSD-WANCISAZero-dayVulnerability management

Earlier coverage of Cisco

All Cisco coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.