Newsletter

One encoded letter hands attackers admin on Cisco SD-WAN Manager

Sent · Daily Briefing
Future Technology

New article published

Security

One encoded letter hands attackers admin on Cisco SD-WAN Manager

Cisco's main indicator of compromise for CVE-2026-76504 is a single character: the letter j, URL-encoded as %6a. Attackers are using requests like that against a critical zero-day in Catalyst SD-WAN Manager to get admin access without a password, BleepingComputer reports.

Key Takeaways

  • Cisco CVE-2026-76504 lets unauthenticated attackers act as admin on every Catalyst SD-WAN Manager deployment, and it is already being exploited
  • There is no workaround; fixed releases start at 20.9.10.1 and CISA gave US federal agencies until 3 October
  • Apple's CoreGraphics flaw CVE-2026-86950 was used in targeted attacks and is fixed in iOS 26.7.1 and macOS Tahoe 26.7.1

You received this because you subscribe to Future Technology.

← Back to the archive

Get the briefing

The biggest tech story, explained in 3 minutes. Delivered free every weekday.

Trusted by thousands of readers