Security NEXT•October 1, 2026•🇯🇵Translated from Japanese

Cisco Patches Critical Zero-Day Authentication Bypass in Catalyst SD-WAN Manager

Cisco Systems has issued security updates for Cisco Catalyst SD-WAN Manager after discovering a zero-day vulnerability that is already being actively exploited in the wild.

The company disclosed the issue in a security advisory published on September 30, 2026. The vulnerability, identified as CVE-2026-76504, is an authentication bypass flaw caused by improper handling of URI encoding in HTTP requests.

By sending specially crafted requests to certain APIs, an attacker can circumvent access controls and obtain remote administrative privileges without valid credentials. The flaw received a CVSS v3.1 base score of 9.8 and is rated Critical, the highest severity level.

Cisco confirmed that it observed exploitation of the vulnerability during September 2026. To address the issue, the company released the following fixed versions: 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1.

Customers are urged to apply the updates as soon as possible. In addition to patching, Cisco recommends restricting access to the management interfaces and APIs to trusted sources only.

Related articles

Security NEXT•Vulnerabilities & Exploits

US Authorities Warn of Active Exploitation of Apple CoreGraphics and Cisco SD-WAN Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two newly identified vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-86950 affects Apple iOS, iPadOS, and macOS through a flaw in the CoreGraphics framework that allows out-of-bounds memory writes and potential arbitrary code execution. CVE-2026-76504 impacts Cisco Catalyst SD-WAN Manager, enabling unauthenticated attackers to gain administrative access due to improper URI encoding handling in the API. Federal agencies must remediate both issues within three days of their respective catalog additions. CISA also requires organizations to check for signs of compromise in addition to applying patches. The alerts highlight ongoing risks to widely deployed Apple operating systems and enterprise SD-WAN infrastructure.

Hispasec•Vulnerabilities & Exploits

Hackers Exploit Two Critical Citrix NetScaler Zero-Days to Deploy Web Shells and Enable Lateral Movement

Two critical zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild to achieve unauthenticated remote code execution. Attackers deploy password-protected PHP web shells such as WHIPSHOT and use the Python-based SLAPSHOT tunneling tool for lateral movement inside targeted networks. The flaws affect NetScaler ADC and NetScaler Gateway appliances with default configurations, and one requires DTLS enabled on VPN vServers. Citrix has released patches for versions 13.1-64.23 and 14.1-73.37, while CISA added the issues to its KEV catalog with a September 30, 2026 remediation deadline for U.S. federal agencies. Organizations are advised to hunt for indicators including modified httpd.conf entries, anomalous setuid permissions on /bin/sh, and suspicious files in /var/netscaler/logon/LogonPoint/custom before applying updates.

Security NEXT•Vulnerabilities & Exploits

Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ

SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.

BoletimSec•Vulnerabilities & Exploits

WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution

WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.