Join Nostr
2026-09-30 18:34:31 UTC

Dark Web Informer :verified_paw: on Nostr: 🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited ...

🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited

CVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager.

The flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges.
â €
The vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration.

Cisco became aware of active exploitation in September after investigating a support case.
â €
There are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.

Source: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/