Security

One encoded letter hands attackers admin on Cisco SD-WAN Manager

(today) · 2 min read · By Future Technology

Key takeaways

  • Cisco CVE-2026-76504 lets unauthenticated attackers act as admin on every Catalyst SD-WAN Manager deployment, and it is already being exploited
  • There is no workaround; fixed releases start at 20.9.10.1 and CISA gave US federal agencies until 3 October
  • Apple's CoreGraphics flaw CVE-2026-86950 was used in targeted attacks and is fixed in iOS 26.7.1 and macOS Tahoe 26.7.1

Cisco's main indicator of compromise for CVE-2026-76504 is a single character: the letter j, URL-encoded as %6a. Attackers are using requests like that against a critical zero-day in Catalyst SD-WAN Manager to get admin access without a password, BleepingComputer reports.

The Cisco SD-WAN zero-day is rated CVSS 9.8, affects every deployment regardless of configuration, and is the fifth actively exploited SD-WAN zero-day disclosed this year.

How the Cisco SD-WAN zero-day works

Catalyst SD-WAN Manager, formerly vManage, is the dashboard admins use to run up to 6,000 SD-WAN devices from one place. In its security advisory, Cisco says the bug comes from improper handling of URI encoding in HTTP requests. A crafted request slips past an authentication rule meant to protect a specific API endpoint, and the attacker lands with admin privileges.

Very roughly, the security check reads the URL one way and the server reads it another. Encoding a single character is enough to fall through the gap.

Cisco says it became aware of active exploitation in September. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 30 September and gave US federal agencies until Saturday 3 October to secure their systems.

What SD-WAN admins should do now

There is no workaround, so upgrading is the fix. Cisco's first fixed releases are:

  • 20.9: upgrade to 20.9.10.1
  • 20.12: upgrade to 20.12.8.2
  • 20.15: upgrade to 20.15.6.1
  • 20.18: upgrade to 20.18.4.1
  • 26.1: upgrade to 26.1.2.1
  • 26.2: upgrade to 26.2.1
  • Anything older than 20.9: migrate to a fixed release

To check for compromise, Cisco suggests searching serviceproxy-access.log under /var/log/nms/containers/service-proxy and vmanage-server.log under /var/log/nms/ for j_security_check entries from unknown IP addresses. Keeping management interfaces off the open internet remains sensible advice while you schedule the upgrade.

This lands only weeks after the Cisco Secure Email Gateway flaw we covered. Management appliances keep getting targeted for a simple reason: one hole gives control of everything behind them.

Apple's CoreGraphics zero-day is on your phone

The second exploited bug this week is closer to home. CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the framework that renders images and documents across Apple devices. A maliciously crafted file can let an attacker run code. Apple says it is aware the flaw may have been exploited in an "extremely sophisticated attack" against specific individuals on iOS versions released before iOS 27, Help Net Security reports.

Apple shipped fixes on 28 September in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, TidBITS notes. Affected hardware includes iPhone 11 and later.

So: open Settings, then General, then Software Update. Attacks like this usually start with high-value targets such as journalists and activists, but the patch is the same for everyone.

The order of the patch pile

If you already worked through September's Patch Tuesday, this week's order is short. SD-WAN Manager comes first if you run it, then every Apple device in the house.

The federal deadline for the Cisco bug is two days away, which tells you how quickly CISA expects attackers to scale this up.

More from Future Technology