Cisco SD-WAN Zero-Day Hands Out Admin Access (09/30/2026)
- › Cisco says attackers are exploiting CVE-2026-76504, rated 9.8, to use the Catalyst SD-WAN Manager API with admin privileges and no credentials.
- › There is no workaround, so the fix is an upgrade and, until then, keeping the Manager off the open internet.
- › Bitget's investigators trace the first malicious activity on its third-party security appliances to August 31, more than three weeks before the theft.
- › TeamViewer fixed five high-severity flaws in version 15.82, including a remote session access control bypass that could lead to code execution.
- › A pre-authentication flaw in MikroTik RouterOS web management can give root code execution from a single crafted request.
Cisco’s advisory today is about the device that tells every branch router what to do. An SD-WAN Manager holds the configuration for the whole network, and CVE-2026-76504 lets an attacker with no account use its API as the most privileged user on the system. Cisco learned of the exploitation while handling its own support cases, which means at least some customers were already compromised by the time they called for help.
Top 5 Critical Security Alerts
1. Cisco Catalyst SD-WAN Manager Zero-Day Grants Admin With No Login
Cisco says attackers are exploiting CVE-2026-76504, rated 9.8, in Catalyst SD-WAN Manager, where mishandled URI encoding lets a remote attacker bypass an authentication rule and use the Manager’s API with the privileges of the admin user, which holds the role “allowed to perform all operations on the device,” per The Hacker News and BleepingComputer. Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1, and earlier trains need to migrate. There is no workaround.
Operator Note: Nothing that configures your entire WAN belongs on the internet. Upgrade, restrict Manager access to known management hosts behind a firewall, and review the Manager’s audit logs for configuration changes and new accounts from September onward.
2. Bitget’s Attacker Was Inside Its Security Appliances for Weeks
Bitget’s investigators found the earliest malicious activity on August 31, when an attacker exploited a zero-day in a service on a node of a third-party security product, per BleepingComputer. Hidden scripts appeared on more nodes between September 23 and 25, the attacker gained privileged access to two of the exchange’s security appliances on September 24, and then moved laterally to the production wallet job server, where a custom withdrawal tool took $387.5 million from hot and warm wallets over about three hours on September 25. The reports do not name the vendor.
Operator Note: Three and a half weeks passed between first access and theft, and the foothold was a security product. Make sure appliance logs leave the appliance, and treat an unexplained script on a security node as an incident on the day you find it.
3. TeamViewer Fixes Five High-Severity Flaws
TeamViewer urged customers to update to version 15.82 after fixing five high-severity flaws in its client and host software for Windows, Linux, and macOS, per BleepingComputer. The most serious, CVE-2026-92370, is a remote session access control bypass that could lead to remote code execution, and the other four could let a local attacker escalate to SYSTEM or root. TeamViewer says it knows of no public disclosure or exploitation.
Operator Note: Remote access software is on the short list of things attackers install on purpose, so an old copy nobody manages is a gift. Inventory every TeamViewer install, including the ones individual staff put on for a vendor, and update or remove them.
4. MikroTik RouterOS Flaw Allows Root Code Execution Before Login
CISA warned of CVE-2026-84411, a critical pre-authentication integer underflow in MikroTik RouterOS web management that lets a single crafted request produce code execution with root privileges or a denial of service, per BleepingComputer. No exploitation has been reported, but RouterOS flaws are frequent targets for attackers and botnets.
Operator Note: Turn off web management on the WAN interface of every MikroTik device you own, then schedule the upgrade to the fixed release.
5. CSuite Phishing Takes Microsoft 365 Sessions and Installs Remote Tools
ANY.RUN researchers traced a phishing operation called CSuite across 351 sandbox analyses, with 51% of submissions from the United States, using Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365 lures, per The Hacker News. One path drops installers that set up ScreenConnect or Action1, and the other pushes victims into credential harvesting or device code phishing to capture Microsoft 365 sessions, with technology, manufacturing, government, and consulting organizations most exposed.
Operator Note: Block device code flow for users who have no need for it, and alert on any remote management tool installed outside your own software deployment process.
Additional Security Alerts
Threat Intelligence
- Microsoft details post-exploitation of the Zimbra SNMP flaw: Attackers exploiting CVE-2026-73570 deployed JSP web shells, escalated to root, installed a systemd service for persistence, harvested LDAP secrets, and exfiltrated data with AzCopy. We covered the flaw on August 25. Microsoft Security
- Researchers publish the pre-authentication path in the Citrix NetScaler flaw: Technical details of CVE-2026-88772 show how it reaches shellcode execution, which tends to bring in more attackers. The Hacker News
- Ukraine warns of Russian mobile malware including an iPhone exploit kit: The SSSCIP says the “hit and run” iPhone malware DarkSword is part of a wave of attacks on iOS and Android. The Record
- China-nexus UAT-11587 targets government and policy groups across Asia: Cisco Talos found a previously undocumented backdoor, Antino, used against organizations in Taiwan, India, the Philippines, and Cambodia. Cisco Talos
Security Breaches & Incidents
- South Africa seeks help after an attack on air traffic control: A ransomware toolkit was found on at least one operational network. Dark Reading
Vulnerabilities & Patches
- OpenSSL fixes a high-severity DTLS flaw: A retransmitted handshake message can leak heap memory unencrypted to the other side of the connection or crash the program. The Hacker News
- Microsoft will block script injection into Entra ID sign-in pages from October: Microsoft reminded customers that the protection takes effect next month. BleepingComputer
- Google says AI-found vulnerabilities are more likely to enable remote code execution: Disclosures and exploitation of AI-discovered flaws are both rising. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.