Cisco has released crucial updates to address a severe security flaw in its Catalyst SD-WAN Manager software. The vulnerability, actively exploited in real-world scenarios, allows unauthorized attackers to gain administrative control over affected systems without authentication.
Details of the Security Flaw
Identified as CVE-2026-76504, the flaw scores 9.8 on the CVSS scale, indicating its critical nature. The issue affects the API’s session-based authentication, stemming from improper URI encoding handling in HTTP requests.
Attackers can exploit this by sending specially crafted HTTP requests to the system’s API, effectively bypassing authentication and accessing the system with administrative privileges. All configurations of the Catalyst SD-WAN Manager are susceptible, and no temporary solutions are available.
Remediation and Recommendations
Cisco urges users to update to fixed software versions: 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. The company has also provided indicators of compromise to assist security teams in detecting potential breaches.
Additionally, Cisco has offered general guidelines for strengthening vulnerable systems. The US Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities list, directing federal entities to apply patches within a tight timeframe.
Industry Reactions and Future Outlook
Jake Knott, head of threat intelligence at WatchTowr, noted that Cisco SD-WAN frequently appears on CISA’s exploitation lists. He highlights the platform’s attractiveness as a target due to its widespread use in managing extensive networks.
Organizations are strongly advised to implement the recommended updates immediately and to monitor their systems for suspicious activity, such as unauthorized URL-encoded POST requests, to prevent potential security breaches.
With the increasing focus on network vulnerabilities, maintaining up-to-date systems and following expert advice are crucial steps in safeguarding digital infrastructures.
