Cisco Warns That Hackers Are Exploiting a Critical Security Flaw in Network Management Systems

Businesses using Cisco networking equipment are being warned about a serious security problem that attackers are already taking advantage of. Cisco has confirmed that hackers are actively exploiting a newly discovered flaw in Cisco Catalyst SD-WAN Manager, a system businesses use to manage and control their networks.

The vulnerability is particularly concerning because an attacker does not need a username or password to take advantage of it. If the affected management system is accessible from the internet, an attacker may be able to send a specially designed request that bypasses the system’s normal login protections.

In simple terms, imagine a building with a locked front door. Normally, you would need a key or access card to get inside. This vulnerability creates a way for someone to convince the building’s security system that they are already authorized, allowing them to get through without having the proper credentials.

The problem has been identified as CVE-2026-76504 and has been given a severity rating of 9.8 out of 10, putting it in the critical category. Cisco says the issue affects the part of SD-WAN Manager responsible for handling login sessions and certain requests made through the system.

The vulnerability is caused by the way the software processes certain web addresses. By slightly changing how a request is written, an attacker can potentially bypass a security check that is supposed to prevent unauthorized access.

What makes this particularly serious is the level of access an attacker could potentially obtain. The attack can allow someone to interact with the system as an administrator without actually knowing the administrator’s password. An administrator account typically has broad control over the network, meaning a successful attack could give criminals significant control over the organization’s networking environment.

Cisco became aware that the vulnerability was being actively exploited in September 2026. The company discovered the issue while helping a customer through a technical support case and subsequently determined that attackers were already using the weakness.

At this time, Cisco has not publicly explained how many organizations have been targeted, who is behind the attacks, or exactly what attackers did after gaining access. That means businesses should treat the vulnerability seriously even if they don’t yet know whether their own systems have been targeted.

Cisco has released software updates that fix the problem. Organizations using affected versions of SD-WAN Manager should upgrade to the appropriate fixed version for their software release. Simply having installed an earlier Cisco security update may not be enough because this is a separate vulnerability.

For businesses that cannot immediately install the update, Cisco recommends limiting who can connect to the management system. In particular, companies should avoid making administrative management systems directly accessible from the public internet whenever possible.

This is an important security practice even beyond this particular vulnerability. Network management systems are designed to control important parts of a company’s technology infrastructure, so they should generally be accessible only to trusted users and devices.

Businesses can also place these management systems behind a firewall and restrict access to known, trusted locations. For example, instead of allowing anyone on the internet to reach the management system, an organization could allow access only from its internal network or from specific systems used by its IT staff.

Companies that believe their systems may have been compromised should also look for signs that someone has attempted to exploit the vulnerability. Cisco has identified certain unusual requests that may appear in system logs and could help security teams determine whether an attacker has tried to gain unauthorized access.

However, seeing one of these requests does not automatically mean a system was successfully compromised. Some of the same entries can occur during normal system activity, so they need to be reviewed in context.

Organizations that are unsure whether their systems have been affected can also work with Cisco’s technical support team to investigate. Cisco recommends collecting diagnostic information from the affected system so security specialists can examine it for signs of suspicious activity.

The discovery of this vulnerability is another reminder that attackers frequently target the technology businesses rely on to manage their networks. Network management systems can be especially attractive because gaining access to them may provide a much broader view and level of control than compromising an individual employee’s computer.

It also highlights why security updates should not be treated as optional maintenance. When a software maker confirms that attackers are already exploiting a vulnerability, delaying an update can leave an organization exposed to an active threat.

For businesses using Cisco Catalyst SD-WAN Manager, the most important steps are straightforward: determine whether the organization is running an affected version, install the appropriate security update, restrict unnecessary internet access to the management system, and investigate the system for signs of suspicious activity.

For everyone else, the broader lesson is worth remembering. Cyberattacks don’t always begin with a suspicious email or an employee clicking on a dangerous attachment. Sometimes attackers target the behind-the-scenes systems that businesses use to operate their networks.

Those systems may not be visible to everyday employees, but they can be among the most important pieces of technology inside an organization. Keeping them updated, limiting who can access them, and monitoring them for unusual activity can make it much harder for attackers to turn a software vulnerability into a larger security incident.