Cisco has released security updates for a critical zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2026-76504, which attackers are actively exploiting to gain administrator privileges.
Catalyst SD-WAN Manager (formerly known as SD-WAN vManage) is network management software that allows administrators to monitor and manage SD-WAN devices from a central dashboard.
Cisco said its Product Security Incident Response Team became aware of active exploitation in September 2026 and urged customers to upgrade to a fixed software release. The vulnerability affects all deployments regardless of configuration.
The flaw, which resides in SD-WAN's API session-based authentication, stems from improper handling of URI encoding in HTTP requests. An attacker can send a specially crafted request that bypasses an authentication rule protecting a specific API endpoint, allowing remote, unauthenticated access with administrator privileges.
Cisco said attackers are using the URI-encoded value %6a, which represents the character j, in malicious requests. The company has not disclosed further technical details about the attacks.
Administrators are advised to review serviceproxy-access.log under /var/log/nms/containers/service-proxy and vmanage-server.log under /var/log/nms/. Cisco recommends looking for requests involving j_security_check originating from unknown or unauthorized IP addresses.
In a separate report, Microsoft has warned that threat actors are exploiting a patched Zimbra Collaboration Suite vulnerability (CVE-2026-73570) to remotely execute commands, deploy web shells, and access email and authentication data. The flaw affects exposed servers with SNMP enabled and was patched in Zimbra 10.1.20 in July 2026. Attackers have been observed using persistence and privilege-escalation techniques, though the group behind the attacks remains unknown.
The US Cybersecurity and Infrastructure Security Agency (CISA) has released an unrelated warning detailing a vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition (CVE-2026-84411). The vulnerability is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling. CISA says that currently there’s no indication that the flaw is being exploited in the wild.