MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-30 · via The Hacker News

Cisco SD-WAN Manager Zero-Day Allows Admin-Level API Access Without Credentials

Image via The Hacker News
Image via The Hacker News

Cisco has disclosed active exploitation of a critical zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that permits attackers to access administrative APIs without valid login credentials. The flaw enables unauthorized remote actors to gain full admin privileges over SD-WAN network infrastructure with no required workaround currently available. Cisco has released patched versions to address the vulnerability.

Expanded Detail

A critical vulnerability has been identified in Cisco's Catalyst SD-WAN Manager platform, a networking tool used to manage software-defined wide-area network deployments across organizations. The flaw allows remote attackers to bypass authentication mechanisms entirely, granting them the same access level that legitimate administrators possess. This represents a significant risk because SD-WAN infrastructure typically controls traffic routing and connectivity across distributed enterprise networks.

The vulnerability is particularly concerning because it has already been observed in active attacks in the wild, indicating that threat actors are actively exploiting the flaw. Cisco has responded by releasing updated software versions to remediate the issue, though organizations running vulnerable versions face exposure until patches are deployed.

Context

Organizations relying on Catalyst SD-WAN Manager for network management could face substantial operational risk from this vulnerability. Compromised SD-WAN infrastructure may allow attackers to intercept, redirect, or disrupt network traffic, potentially affecting business continuity and data security across multiple locations. The absence of a temporary workaround may leave some organizations exposed during the patch deployment window, particularly those with complex networks requiring extensive testing before updates.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Cisco Releases Patches for Actively Exploited Network Management Platform Vulnerability · Cybersecurity
OpenInfra Foundation Warns of Compromised Software Repository Following Exploitation of Unpatched Authentication Bypass Flaw · Cybersecurity
Critical Zimbra Vulnerability Allows Unauthorized Remote Code Execution and Data Theft · Cybersecurity
Active exploitation of Zimbra vulnerability allows attackers to deploy web shells and harvest corporate emails · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager.” Browse more stories.