Skip to content

Cisco warns of actively exploited SD-WAN zero-day

Cisco has patched a zero-day vulnerability in its SD-WAN Manager networking software which attackers are already exploiting in the wild.

Cisco warns of actively exploited SD-WAN zero-day
Image credit: https://unsplash.com/@ikukevk

Cisco has patched a zero-day vulnerability in its SD-WAN Manager networking software, and advised customers Wednesday that attackers are already exploiting it in the wild.

The flaw, which Cisco — one of the world’s largest networking and cybersecurity vendors — has filed under CVE-2026-76504, allows a remote hacker without a username or password to bypass authentication and obtain administrator-level access to the affected system.

It has been given a severity score of 9.8 out of 10 and is the latest in a litany of vulnerabilities added to Cisco's KEV catalogue in 2026 by CISA, the US department of Homeland Security's cybersecurity arm. In total, 17 Cisco zero-days have been recorded this year, compared with eight in 2025 and six in 2024.

The latest fixed release is 26.2.1. Cisco has also published indicators of compromise (IOCs) that defenders can use to check for signs of attack. "There are no workarounds that address this vulnerability," Cisco said in its summary.

Indicators of Compromise

Cisco released the following details on the vulnerability:

Cisco Catalyst SD-WAN Manager systems that are exposed to the internet and that have ports exposed to the internet are at risk of exposure to compromise. In some instances, these indicators of compromise (IOCs) may occur during standard operations. Therefore, they must be assessed against normal network posture to identify and avoid false positives.

Important: These IOC examples show the use of %6a as the URI encoded character j in the request. This is only an example, and the vulnerability will allow any one character that is encoded in the request to be used to exploit this.

Customers are encouraged to audit the serviceproxy-access.log file, located at /var/log/nms/containers/service-proxy/serviceproxy-access.log, for entries that are related to j_security_check from unknown or unauthorized IP addresses, as shown in the following example:

[2026-09-29T23:11:13.948-05:00] "POST /%6a_security_check HTTP/1.1" 200 - 48 0 4 - "10.10.10.47,192.168.1.174" "Mozilla/5.0" "92980fc6-bb3c-4b67-8a6d-af5ceb236d4c" "vmanage-9999.example.com" "127.0.0.1:8080"


Customers are encouraged to audit the vmanage-server.log file, located at /var/log/nms/vmanage-server.log, for entries that are related to j_security_check from unknown or unauthorized IP addresses, specifically being called for users that include names starting with viptela-reserved-, as shown in the following example:

29-Sep-2026 23:11:13,952 CDT [] [vManage-new] [UserUtils] (default task-127462) |default| Request Stored in Map is (/%6a_security_check) for user (viptela-reserved-..)


For help determining if Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco Technical Assistance Center (TAC). Cisco TAC cases should be opened as a Severity 3 with the CVE-ID CVE-2026-76504 in the title. Before opening a new TAC case, customers are encouraged to use the request admin-tech command from the Cisco Catalyst SD-WAN Manager (vManage) in the SD-WAN deployment so that the admin-tech file can be provided to the Cisco TAC for review.

The viptela-reserved system service accounts are documented in the Authentication, Authorization, and Accounting section of the Cisco Catalyst SD-WAN Systems and Interfaces Configuration Guide.

The disclosure comes a fortnight after Cisco patched another exploited authentication bypass, CVE-2026-76460, affecting its Identity Services Engine software. That vulnerability carried the maximum 10.0 severity score.

Cisco became aware of the latest zero-day after looking into a customer support case. It is not known who orchestrated the attack, nor how many organisations have been compromised as a result.

The Stack keeps its security reporting free for public interest purposes. You can support our independent journalism and grab a 50% discount to tickets for our events by subscribing for $300/year.

Add The Stack on Google