MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-30 · via BleepingComputer

Cisco Releases Patches for Actively Exploited Network Management Platform Vulnerability

Image via BleepingComputer
Image via BleepingComputer

Cisco disclosed a critical zero-day vulnerability in its Catalyst SD-WAN Manager that attackers are currently weaponizing to bypass authentication and gain administrator access to network infrastructure management systems. The flaw stems from improper URI encoding handling that allows unauthenticated attackers to send crafted API requests that circumvent intended authentication controls. This represents the fifth actively exploited SD-WAN zero-day discovered in 2026, prompting urgent patching recommendations across affected software versions.

Expanded Detail

The vulnerability exploits a flaw in how the system processes web requests, specifically in the encoding of characters within URLs. By disguising malicious requests with a specific encoded character, attackers can slip past security checkpoints designed to protect administrative functions. The SD-WAN Manager platform is particularly valuable to attackers because it serves as a central control point for thousands of network devices across an organization.

This marks a concerning pattern for Cisco's SD-WAN products. Since the start of 2026, the company has disclosed multiple zero-day flaws affecting these systems, several allowing attackers to obtain highest-level system access. Federal agencies have been given just days to apply fixes, underscoring the severity that government cybersecurity officials assess for this particular threat.

Context

Organizations relying on Cisco's SD-WAN infrastructure may face significant operational risk if systems remain unpatched, as successful exploitation could grant attackers broad control over network management and potentially thousands of connected devices. Enterprises with geographically distributed networks could experience cascading impacts across multiple locations. However, the availability of patches and detailed detection guidance may allow well-resourced security teams to mitigate exposure relatively quickly, though organizations with legacy or less-monitored deployments could remain vulnerable for extended periods.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Cisco SD-WAN Manager Zero-Day Allows Admin-Level API Access Without Credentials · Cybersecurity
OpenInfra Foundation Warns of Compromised Software Repository Following Exploitation of Unpatched Authentication Bypass Flaw · Cybersecurity
Federal Cybersecurity Agency Alerts to Critical Unauthenticated Vulnerability in Popular Router Software · Cybersecurity
Critical Zimbra Vulnerability Allows Unauthorized Remote Code Execution and Data Theft · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Cisco warns of new SD-WAN zero-day exploited in attacks.” Browse more stories.