# Cisco warns of new SD-WAN zero-day exploited in attacks

DevFeed: [Cisco warns of new SD-WAN zero-day exploited in attacks](<https://devfeed.tech/articles/cisco-warns-of-new-sd-wan-zero-day-exploited-in-attacks-62466.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/>)

Author: Sergiu Gatlan

Published: 2026-09-30T14:46:40Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [SD-WAN](<https://devfeed.tech/topics/sd-wan.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cisco Catalyst Center](<https://devfeed.tech/topics/cisco-catalyst-center.md>), [CVE-2026-41456](<https://devfeed.tech/topics/cve-2026-41456.md>)

Tags: [active-exploitation](<https://devfeed.tech/tags/active-exploitation.md>), [actively-exploited](<https://devfeed.tech/tags/actively-exploited.md>), [api](<https://devfeed.tech/tags/api.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication-bypass](<https://devfeed.tech/tags/authentication-bypass.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [catalyst-sd-wan](<https://devfeed.tech/tags/catalyst-sd-wan.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-sd-wan-vmanage](<https://devfeed.tech/tags/cisco-sd-wan-vmanage.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [dashboard](<https://devfeed.tech/tags/dashboard.md>), [deployments](<https://devfeed.tech/tags/deployments.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [network](<https://devfeed.tech/tags/network.md>), [sd-wan](<https://devfeed.tech/tags/sd-wan.md>), [security](<https://devfeed.tech/tags/security.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [windows](<https://devfeed.tech/tags/windows.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

## AI overview

Cisco released security updates for a critical, actively exploited zero-day in Catalyst SD-WAN Manager. CVE-2026-76504 allows unauthenticated remote attackers to bypass API authentication and gain admin privileges. Cisco recommends upgrading to a fixed release and provides indicators and log locations to help administrators investigate possible compromise.

## Source excerpt

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]