Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco Catalyst SD-WAN Manager actively exploited authentication-bypass zero-day (CVE-2026-76504)

Vulnerability
First reported
Last updated
Happening score
H score 56
2 unique sources, 2 articles

Summary

Hide ▲

Cisco's fix for CVE-2026-76504 in Catalyst SD-WAN Manager closes a critical zero-day that was being actively exploited to reach admin privileges. The flaw affects all deployments and enables unauthenticated remote access through API session-based authentication management. Cisco told customers to move to a fixed software release and shared log indicators to help identify abuse.

Related Happenings

Cisco Catalyst SD-WAN unauthorized peering and SSH access campaign

Campaign
H score38 First: 25.06.2026 17:15 Last: 25.06.2026 17:15 Sources 1

About this happening: An active campaign used unauthorized peering connections and SSH access to maintain footholds inside a service provider's Cisco Catalyst SD-WAN environment, increa...

CISA adds CVE-2026-20262 to KEV and orders federal fixes

Public Sector Action
H score32 First: 16.06.2026 09:05 Last: 16.06.2026 09:05 Sources 1

About this happening: CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...

Cisco Catalyst SD-WAN Manager actively exploited file upload overwrite flaw (CVE-2026-20262)

Vulnerability
H score24 First: 15.06.2026 20:12 Last: 15.06.2026 20:12 Sources 1

About this happening: Cisco Catalyst SD-WAN Manager was patched for CVE-2026-20262 after attackers used it to create or overwrite files and escalate to root across all deployment type...

Cisco Catalyst SD-WAN Manager root privilege escalation flaw (CVE-2026-20245)

Vulnerability
H score60 First: 05.06.2026 09:24 Last: 05.06.2026 09:24 Sources 1

About this happening: CVE-2026-20245 in Cisco Catalyst SD-WAN Manager is an actively exploited high-severity vulnerability that can let an authenticated local attacker with netadm...

Latest development: 06.06.2026 07:19

Cisco warned that CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, is under active exploitation and can let an authenticated local attacker with netadmin privileges upload a crafted file to execute arbitrary commands as root. Cisco said the flaw affects On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP), that limited exploitation has already resulted in configuration changes pushed to edge devices, and that no patches or mitigations are currently available. Cisco also advised checking /var/log/scripts.log for indicators of compromise and credited Google Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan with discovering and reporting the issue.

Cisco Secure Workload REST API validation/authentication flaw (CVE-2026-20223)

Vulnerability
H score49 First: 21.05.2026 15:04 Last: 21.05.2026 15:04 Sources 1

About this happening: Cisco Secure Workload Cluster Software was patched for CVE-2026-20223, a critical REST API flaw that could let attackers gain Site Admin privileges and cross tenan...

Timeline

  1. 30.09.2026 17:46 3 articles · 2h ago

    Cisco warns of actively exploited CVE-2026-76504 in Catalyst SD-WAN Manager

    Initial Disclosure

    Cisco released security updates for CVE-2026-76504 in Catalyst SD-WAN Manager and warned that attackers were actively exploiting the critical zero-day to escalate to admin privileges. Cisco said the flaw affects all deployments, stems from improper handling of URI encoding in an HTTP request, and can let unauthenticated attackers reach vulnerable systems remotely with admin privileges. The company urged customers to upgrade to a fixed software release and review serviceproxy-access.log and vmanage-server.log for %6a and j_security_check entries from unknown or unauthorized IP addresses.

    Show sources