AI Weekly Malaysia

Back to items Summaries

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

ID
30718
Status
summarized
Published
01 Oct 2026, 6:33 PM
Fetched
01 Oct 2026, 8:10 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
01 Oct 2026, 8:11 PM
Tags
Audience
developers

What happened

CISA added CVE-2026-76504, a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog on Wednesday after Cisco confirmed active exploitation in September 2026. The flaw is a hex/URI-encoding handling bug: a crafted HTTP request to the API lets an unauthenticated remote attacker act as the admin user. Cisco published IoCs but not victim counts or attribution, and U.S. federal civilian agencies had until October 3, 2026 to patch — a two-day window. watchTowr's Jake Knott noted eight Cisco SD-WAN CVEs have hit KEV in 2026 alone.

Why it matters

If you or a client run Cisco Catalyst SD-WAN Manager, this is a same-day patch plus log check: grep /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check calls from unknown IPs and for usernames starting with 'viptela-reserved-'. If you don't run that appliance, nothing here changes your week — it is enterprise network gear, not developer tooling, and the useful signal is the pattern (eight SD-WAN CVEs on KEV this year) for anyone doing MSP or enterprise infra work.

Discussion angle

The FCEB patch deadline was two days from KEV listing — is a 48-hour federal patch window realistic for enterprise network appliances, and does an encoding-normalization bug (URI/hex handling) in an API auth path point at a class of bug your own API gateway might share?

Top