Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- ID
- 30406
- Status
- summarized
- Published
- 30 Sep 2026, 11:24 PM
- Fetched
- 01 Oct 2026, 1:13 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 01 Oct 2026, 1:14 AM
- Tags
- Audience
- developerssaas_founders
What happened
Cisco disclosed on September 30 that attackers are actively exploiting CVE-2026-76504 (CVSS 9.8), an authentication bypass in Cisco Catalyst SD-WAN Manager's login-session API: a crafted HTTP request with malformed URI encoding slips past an auth rule meant to protect a single endpoint, letting an unauthenticated remote attacker act as the admin user, which by default holds the netadmin role. There is no workaround — only fixed releases, starting at 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, with trains earlier than 20.9 told to migrate. Cisco's TAC found it during a support case, and the advisory gives no victim count, start date, attribution, or post-exploitation detail.
Why it matters
This only forces action on you if you or your employer run Cisco Catalyst SD-WAN Manager — but if you do, the decision is immediate: internet-exposed Managers can be compromised with zero credentials and there is no workaround, so you must patch or take it off the public internet today. Note the version trap: because this fix table lists newer builds than the May (CVE-2026-20182) and June (CVE-2026-20245, CVE-2026-20262) advisories, a Manager you already patched for those is still vulnerable, and Cisco's table omits the 20.10–20.16 trains its May advisory covered, so confirm your train's fix with Cisco rather than assuming. For everyone else this is a low-priority read, though the bug class — an API gateway or router mishandling URI encoding so a path-normalisation rule fails open — is worth checking in your own auth middleware.
Discussion angle
The interesting engineering bit isn't Cisco's patch list, it's the failure mode: an authentication rule scoped to one API endpoint was bypassed purely through URI encoding, so the request never matched the protected path. Ask who in the room has auth or rate-limit rules keyed on URL paths in an API gateway or reverse proxy, and whether they've tested those rules with encoded, double-encoded, or trailing-slash variants — that's the same class of bug and it's testable this week.