decrypted · 1 october 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain
Cisco's SD-WAN manager was exploited before it was patched, and it should never face the internet
Cisco has confirmed that attackers were abusing a critical flaw in Catalyst SD-WAN Manager before a fix existed, and patches have only just arrived. Tracked as CVE-2026-76504 and scored 9.8 out of 10, it lets an unauthenticated attacker act as the administrator of the system that steers a company's wide area network. Cisco says it learned of exploitation in September. NHS England's cyber team assesses further exploitation as highly likely. If your organisation links offices, branches or clinics with SD-WAN, this is today's job.
A spelling trick at the front door
Cisco describes the fault as improper handling of URI encoding in an HTTP request. In plain English: a web address can write the same character two ways, as itself or as a percent code. The letter j, for example, can also appear as %6a. Picture a doorman with a list of rooms guests may not enter. He reads each badge literally and waves through anything that does not match a forbidden name. The staff inside read the badge more cleverly, and a name written in an unexpected hand still sends the guest to the forbidden room. The check and the action disagree about what the request says, and the attacker lives in that gap.
The result is that a crafted request reaches the management API with the privileges of the admin user. Cisco says all configurations are affected and has not said who is behind the attacks.
What defenders will see
The clue is in the logs. Cisco advises searching the service proxy access log for requests to j_security_check that contain encoded characters such as %6a. Press coverage adds that the vManage server log, and login names beginning "viptela-reserved-", deserve a look, though false positives are possible.
There is no workaround. The fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, and anything older than 20.9 must move to a fixed release. NHS England's advice is to run a compromise assessment before patching so that evidence is not overwritten, then report anything found. Patching closes the door but does not tell you who already walked through it.
The Secure by Design lesson
A controller that can reconfigure every branch router should not answer to the internet at all. Cisco's own mitigation is to restrict access from unsecured networks and allow only known, trusted hosts. That is the design decision that turns this from an emergency into a footnote: put the management plane on a private path, reachable by allow-list or strongly authenticated VPN, so that a bug in the login code is a bug nobody can reach.
A vendor lesson too. Convert a request to one canonical form before deciding whether it is allowed, not after. Management consoles are prized because one compromise reaches every site they control.
The cost of applying this is modest in money and larger in knowledge. A firewall rule takes an afternoon. Knowing whether your manager is internet-facing, which version it runs and who reads its logs takes an asset inventory many organisations do not have. Ask your IT lead or managed service provider those three questions before the weekend. The NCSC's Citrix alert this week also began with isolating affected systems.
Also this week
Ransomware. European police announced the takedown of the KillSec extortion gang, with arrests, eight house searches including in the UK, five servers seized and at least 110 terabytes of stolen data secured, according to Eurojust. A 16-year-old is suspected to be the main operator. Eurojust says the group got in through poorly secured access, particularly linked to cloud storage. Takedowns help, but those access paths are the same ones every other gang tries. Dull, preventable and fixable: private-by-default storage and strong authentication.
Cloud. Truffle Security found 543,699 still-working credentials in public GitHub repositories, using a dataset built to train language models. Its finding that matters: providers that automatically revoke leaked keys saw near-zero survival, while services without revocation exceeded 80 per cent. It also reports that 51.8 per cent of live credentials are a shape GitHub's default push protection does not recognise. Secure by Design here means short-lived credentials by default, not clean-up by hand.
Supply chain. Researchers at OX Security describe PhantomSub, 101 npm packages abusing the Baileys WhatsApp library to enrol developers' accounts in spam channels, with about 490,000 downloads. OX found no direct data theft, and 16 packages had been removed by 28 September while most stayed live. The lesson is cheap: a package asking for your personal login deserves a no, and new dependencies deserve a review before they reach a build.
Sources
- Cisco Security Advisory: Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
- NHS England Digital: Critical Zero-Day Vulnerability in Cisco SD-WAN Manager
- NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway
- Eurojust: Teenagers suspected of leading ransomware group arrested during international operation
- Truffle Security: GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.
- OX Security: PhantomSub malicious npm campaign
If you want help working out what your own management systems expose, get in touch.
More like this
- Cloudflare's shared disks kept the last customer's data, and the fix was a default 25 september 2026
- A leaver's forgotten login and a poisoned npm package cost CrowdSec 170 repositories 20 september 2026
- The SSO flaw that let one attacker log in as 138 companies 11 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.