AI Weekly Malaysia

Back to items Summaries

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

ID
30406
Status
summarized
Published
30 Sep 2026, 11:24 PM
Fetched
01 Oct 2026, 1:13 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.5
Created
01 Oct 2026, 1:14 AM
Tags
Audience
developerssaas_founders

What happened

Cisco disclosed on September 30 that attackers are actively exploiting CVE-2026-76504 (CVSS 9.8), an authentication bypass in Cisco Catalyst SD-WAN Manager's login-session API: a crafted HTTP request with malformed URI encoding slips past an auth rule meant to protect a single endpoint, letting an unauthenticated remote attacker act as the admin user, which by default holds the netadmin role. There is no workaround — only fixed releases, starting at 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, with trains earlier than 20.9 told to migrate. Cisco's TAC found it during a support case, and the advisory gives no victim count, start date, attribution, or post-exploitation detail.

Why it matters

This only forces action on you if you or your employer run Cisco Catalyst SD-WAN Manager — but if you do, the decision is immediate: internet-exposed Managers can be compromised with zero credentials and there is no workaround, so you must patch or take it off the public internet today. Note the version trap: because this fix table lists newer builds than the May (CVE-2026-20182) and June (CVE-2026-20245, CVE-2026-20262) advisories, a Manager you already patched for those is still vulnerable, and Cisco's table omits the 20.10–20.16 trains its May advisory covered, so confirm your train's fix with Cisco rather than assuming. For everyone else this is a low-priority read, though the bug class — an API gateway or router mishandling URI encoding so a path-normalisation rule fails open — is worth checking in your own auth middleware.

Discussion angle

The interesting engineering bit isn't Cisco's patch list, it's the failure mode: an authentication rule scoped to one API endpoint was bypassed purely through URI encoding, so the request never matched the protected path. Ask who in the room has auth or rate-limit rules keyed on URL paths in an API gateway or reverse proxy, and whether they've tested those rules with encoded, double-encoded, or trailing-slash variants — that's the same class of bug and it's testable this week.

Top