Dark Web Informer :verified_paw: on Nostr: 🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited ...
🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited
CVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager.
The flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges.
â €
The vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration.
Cisco became aware of active exploitation in September after investigating a support case.
â €
There are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.
Source:
https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
Published at
2026-09-30 18:34:31 UTCEvent JSON
{
"id": "56e24af97d75a4edd45b20d4e0e73b65fb3b3d5f214ba5f29b3b4edcfe6a8e5d",
"pubkey": "3602e3a41b34946d81c007fcf5ae0daae25997b4e04b107e82e56a090c0d9b81",
"created_at": 1790793271,
"kind": 1,
"tags": [
[
"imeta",
"url https://media.infosec.exchange/infosec.exchange/media_attachments/files/117/361/427/147/202/305/original/abe66d195a9633bf.png",
"m image/png",
"dim 1522x855",
"blurhash UFSZ5{xu~Axu-;fQWVj[~Aj[9bay%Mj[s:az"
],
[
"proxy",
"https://infosec.exchange/users/DarkWebInformer/statuses/117361427861570548",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited\n\nCVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager.\n\nThe flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges.\n⠀\nThe vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration.\n\nCisco became aware of active exploitation in September after investigating a support case.\n⠀\nThere are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.\n\nSource: https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/\n\nhttps://media.infosec.exchange/infosec.exchange/media_attachments/files/117/361/427/147/202/305/original/abe66d195a9633bf.png",
"sig": "8ec4a89a4502b2e8d89f2f09e567c871bd368d8c5f285a1524253962c378c8c0e8b4bcc99b9c1b7e270e6e8875aa37b0a3b197ec01b1dd67ca848f0da992dfc3"
}