AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-2 of 2 results

DateProviderScoreSummary
01 Oct 2026, 6:33 PMThe Hacker News3.5 CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

CISA added CVE-2026-76504, a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog on Wednesday after Cisco confirmed active exploitation in September 2026. The flaw is a hex/URI-encoding handling bug: a crafted HTTP request to the API lets an unauthenticated remote attacker act as the admin user. Cisco published IoCs but not victim counts or attribution, and U.S. federal civilian agencies had until October 3, 2026 to patch — a two-day window. watchTowr's Jake Knott noted eight Cisco SD-WAN CVEs have hit KEV in 2026 alone.

Why: If you or a client run Cisco Catalyst SD-WAN Manager, this is a same-day patch plus log check: grep /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check calls from unknown IPs and for usernames starting with 'viptela-reserved-'. If you don't run that appliance, nothing here changes your week — it is enterprise network gear, not developer tooling, and the useful signal is the pattern (eight SD-WAN CVEs on KEV this year) for anyone doing MSP or enterprise infra work.

30 Sep 2026, 11:24 PMThe Hacker News2.5 Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Cisco disclosed on September 30 that attackers are actively exploiting CVE-2026-76504 (CVSS 9.8), an authentication bypass in Cisco Catalyst SD-WAN Manager's login-session API: a crafted HTTP request with malformed URI encoding slips past an auth rule meant to protect a single endpoint, letting an unauthenticated remote attacker act as the admin user, which by default holds the netadmin role. There is no workaround — only fixed releases, starting at 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, with trains earlier than 20.9 told to migrate. Cisco's TAC found it during a support case, and the advisory gives no victim count, start date, attribution, or post-exploitation detail.

Why: This only forces action on you if you or your employer run Cisco Catalyst SD-WAN Manager — but if you do, the decision is immediate: internet-exposed Managers can be compromised with zero credentials and there is no workaround, so you must patch or take it off the public internet today. Note the version trap: because this fix table lists newer builds than the May (CVE-2026-20182) and June (CVE-2026-20245, CVE-2026-20262) advisories, a Manager you already patched for those is still vulnerable, and Cisco's table omits the 20.10–20.16 trains its May advisory covered, so confirm your train's fix with Cisco rather than assuming. For everyone else this is a low-priority read, though the bug class — an API gateway or router mishandling URI encoding so a path-normalisation rule fails open — is worth checking in your own auth middleware.

Top