Breach Watch, September 30, 2026: Cisco SD-WAN Zero-Day Gives Attackers Admin Access
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · September 30, 2026

TL;DR for CISOs: Cisco confirmed that attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager that gives unauthenticated administrative API access, and there is no workaround, only patching. Separately, a Dutch security nonprofit says an autonomous AI agent chained two Zammad zero-days to reach root, Bitget's $387.5 million theft traced back to zero-days in two third-party security products, and an exploited Zimbra flaw is being used to steal mail-server secrets.

BOTTOM LINE FOR CISOS
  1. The tools that manage your network and your security are now the target. Cisco's SD-WAN controller, Zimbra's mail server and the two security products behind Bitget all sit in privileged positions, and each was compromised through an unpatched or unknown flaw.
  2. Management planes should not be reachable from untrusted networks. Cisco's only interim advice for the SD-WAN flaw is to restrict access, which is a control you can apply today while the patch is scheduled.
  3. Machine-speed attacks shorten the time between a vulnerability existing and being used. The DIVD incident, as the nonprofit describes it, ended at network segmentation; that boundary is what limited the damage.

Lead story: Cisco warns that a critical Catalyst SD-WAN Manager flaw is being exploited, with no workaround

CRITICAL · ACTIVELY EXPLOITED
Key facts
Vulnerability: CVE-2026-76504, CVSS 9.8, an API authentication bypass in Cisco Catalyst SD-WAN Manager (formerly vManage)
Root cause: Improper handling of URI encoding in an HTTP request, which lets a crafted request skip an authentication rule
Impact: Unauthenticated remote access to the administrative API
Exploitation: Cisco's product security team says it became aware of active exploitation in September 2026 through a support case. Attacker identity and number of victims have not been disclosed
Fixed releases: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; versions earlier than 20.9 must migrate to a fixed release
Workaround: None. Cisco advises restricting access from untrusted networks and placing control components behind a firewall
CISA: Added to the Known Exploited Vulnerabilities catalog on September 30, with a federal remediation deadline of a few days (reports cite October 2 and October 3)

What happened

Cisco published an advisory on September 30 for a flaw in the web-facing API of Catalyst SD-WAN Manager, the server that administers an organization's SD-WAN fabric. According to Rapid7, an attacker can encode a character in the path of a login endpoint so that the request is no longer matched by the rule that demands authentication, and the request is then served with administrative rights.

Cisco says it learned of in-the-wild use while working a customer support case. SecurityWeek reports that Cisco-managed cloud deployments have already been patched. Everyone else needs to apply a fixed release themselves, because configuration changes do not remove the exposure.

Detection guidance is already available. Rapid7 and BleepingComputer both point to POST requests for an encoded form of the j_security_check path in the service-proxy access log, including requests using usernames that begin with "viptela-reserved-". BleepingComputer also lists the vmanage-server log as a place to look.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, Cisco warns of new SD-WAN zero-day exploited in attacks, September 30, 2026
2. Rapid7, Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild
3. SecurityWeek, Cisco patches exploited Catalyst SD-WAN zero-day vulnerability

What this means for your team

An SD-WAN manager is a control plane. Whoever holds administrative access can see and change how branch and data center traffic is routed, which makes this a network-wide problem rather than a single-server one. A flaw that needs no credentials and has no workaround leaves one decision: patch, and until then reduce who can reach the interface.

Do not stop at the patch. Because exploitation began before the fix was public, systems that were reachable from the internet in September should be treated as possibly accessed. Log review and a check for new administrative accounts or configuration changes belong in the same change window as the upgrade.

Reporting differs on how this ranks among Cisco's SD-WAN problems this year, with outlets counting prior exploited flaws differently. The practical takeaway does not depend on the count: if the manager is exposed, it will be probed, so exposure itself is the control to fix.

Action checklist
  1. Identify every Catalyst SD-WAN Manager instance, including lab and disaster recovery copies, and schedule upgrade to the fixed release for your train.
  2. Until patched, limit management access to known trusted hosts and put the manager behind a firewall, as Cisco advises.
  3. Search service-proxy and vmanage-server logs for encoded j_security_check requests and for "viptela-reserved-" usernames from unfamiliar addresses.
  4. Review administrator accounts, API keys and recent configuration or template changes on the manager, and rotate credentials if anything looks unexpected.

A Dutch security nonprofit says an autonomous AI agent chained two Zammad zero-days to reach root

HIGH · AI-DRIVEN INTRUSION
Key facts
Organization: The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that reports security flaws to system owners; case reference DIVD-2026-00015
Vulnerabilities: CVE-2026-102489 (session hijacking leading to code execution as the zammad user, CVSS 9.4) and CVE-2026-102490 (local privilege escalation to root, CVSS 9.4) in the open-source Zammad ticketing system
Timeline: Intrusion on September 21, disclosed by DIVD on September 24, with the Zammad zero-days identified as the entry route on September 30, per Forkast
Who did it: DIVD attributes the activity to an autonomous AI agent; the operator behind it is unidentified
Containment: Network segmentation limited lateral movement, per Forkast; reports differ on whether data was exfiltrated, so the scope of data accessed should be treated as unconfirmed
Exposure: Zammad says it has more than 2,000 customers and 55,000 users. DIVD advises upgrading to Zammad 7 or taking instances offline

What happened

DIVD reported on September 30 that the break-in it disclosed a week earlier started with two previously unknown flaws in its Zammad help-desk server. One flaw allowed a session to be hijacked and code to run as the application user, and the second turned that foothold into root. Forkast notes the first is exploitable in Zammad 6.3.0 through 6.5.4 and present but not exploitable in 7.0.0 through 7.1.3, while the second affects all versions including the latest alpha.

What makes the case unusual is how DIVD describes the attacker. According to BleepingComputer, the researchers found the activity "loud and very, very messy", with code comments explaining the agent's decisions and password spraying that interfered with its own progress. DIVD called the agent poorly trained and configured, yet it still found and chained two zero-days at machine speed.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, DIVD says Zammad zero-days enabled AI-driven network breach, September 30, 2026
2. Forkast, An autonomous AI agent just breached a vulnerability disclosure nonprofit by chaining two Zammad zero-days

What this means for your team

The AI attribution comes from the victim's own analysis, and the details are still emerging, so hold it as DIVD's assessment rather than a settled fact. The operational point holds either way: an automated actor can move from foothold to root faster than a human responder can open a ticket.

Internal service-desk and ticketing systems are an easy item to overlook. They hold customer messages, attachments and sometimes credentials, and they are often run by a business team with a slow patch cadence. Segmentation worked for DIVD, and it is the control most worth testing in your own environment.

Action checklist
  1. Find any Zammad instances in your organization, including ones run by support or IT teams, and follow DIVD's advice to move to version 7 or take them offline until patched.
  2. Confirm help-desk and ticketing servers cannot reach sensitive internal segments directly, and test that a compromise of one would be contained.
  3. Alert on bursts of failed logins and rapid privilege changes on application servers, since automated tooling produces both quickly.
  4. Ask your incident response team to rehearse a scenario where intrusion to root takes minutes, and check which decisions would still need a human approval.

Bitget's $387.5 million theft traced to zero-days in two third-party security products

HIGH · SUPPLY CHAIN
Key facts
Organization: Bitget, a cryptocurrency exchange
Loss: About $387.5 million moved out over roughly three hours on September 25 across multiple blockchains; The Hacker News reports about $632,700 was later frozen
Root cause: Zero-day flaws in two unnamed third-party security products, referred to in reports as Product A and Product B
Method: Per SlowMist, an attacker ran a hidden script on one product, read a database password from an environment variable, then used compromised employee credentials against the second product's management platform and deployed a custom tool that forged risk-control parameters to approve withdrawals
Earliest activity: August 31, per SlowMist and Bitget
Attribution: Bitget's CEO attributes the attack to North Korean actors, citing IP behavior and on-chain analysis; this is the company's view, and the vendors have not been named
Keys: Bitget says private keys and cold wallets were not affected

What happened

Bitget's earlier statements described a breach of its wallet infrastructure. The newer reporting adds the route: attackers did not break the exchange's own code first, but entered through the security appliances that protect it. Mandiant's investigation, as relayed by The Hacker News, found web shells and command-and-control activity on those appliances before movement into the wallet environment.

The incident was covered in our September 28 edition; today's update matters because it moves the story from "an exchange was robbed" to "security tooling was the entry point." The vendors have not been identified, so no product should be assumed affected based on this reporting alone.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, Bitget hacked via zero-day in third-party security products
2. Cointelegraph, SlowMist traces Bitget hack activity to zero-day exploit
3. The Hacker News, Bitget confirms third-party zero-day behind $387.5 million cryptocurrency theft

What this means for your team

Security products have deep access by design, and a flaw in one inherits that access. Two points in the SlowMist account deserve attention: a secret sitting in an environment variable, and employee credentials that were enough to reach a management console. Those are ordinary hygiene gaps that turned one vendor flaw into a path to the withdrawal system.

Most organizations cannot patch an unknown zero-day. They can limit what a compromised appliance can reach, and make sure a high-value action such as releasing funds does not depend on a single set of parameters that the same intruder can forge.

Action checklist
  1. List the security and management appliances that hold credentials or sit in front of critical systems, and document what each can reach if it is compromised.
  2. Move secrets such as database passwords out of environment variables and into a managed vault with rotation, starting with security tooling.
  3. Require phishing-resistant MFA and network restrictions for every vendor management console, so stolen employee credentials alone are not enough.
  4. For high-value transactions, require approval paths that an intruder cannot satisfy by editing parameters on one system.

Exploited Zimbra flaw gives attackers web shells, root and mail-server secrets

HIGH · ACTIVELY EXPLOITED
Key facts
Vulnerability: CVE-2026-73570, unauthenticated OS command injection in Zimbra Collaboration Suite; The Hacker News reports CVSS 8.9
Condition: Affects deployments before 10.1.20 that have the zimbra-snmp package installed and SNMP notifications enabled
Exploitation window: Microsoft documented activity between July 28 and August 7, 2026
Attacker actions: JSP web shells, privilege escalation to root, credential extraction, and in one case an attempt to move archived data to cloud storage
Fix: Zimbra 10.1.20 or later; CISA has added the flaw to its Known Exploited Vulnerabilities catalog, per both sources

What happened

Reports published September 30 summarize Microsoft's analysis of attacks on mail servers running an optional notification feature. A crafted message path allows commands to run without authentication. Attackers then dropped web shells, read service credentials from the local configuration, and used Zimbra's own SSH identities to move to other nodes in a cluster.

GBHackers reports that recovered authentication keys can be used to forge session tokens, which turns a compromised mail server into access to individual mailboxes without passwords. That detail changes the response: patching alone does not invalidate keys that may already have been stolen.

Evidence

Verified against independently fetched sources:
1. The Hacker News, Attackers exploit Zimbra flaw to deploy web shells and harvest authentication secrets, September 30, 2026
2. GBHackers, Zimbra vulnerability exploited to gain root access and steal mailbox authentication secrets

What this means for your team

Mail servers hold the context attackers use for fraud: invoices, vendor threads and password-reset messages. A mail server compromise is a business email compromise risk even if no data is ever sold.

The vulnerable condition is narrow, since it requires an optional package, which means some teams will conclude they are safe without checking. Verify rather than assume, and treat the secrets, not only the software version, as part of the remediation.

Action checklist
  1. Confirm the Zimbra version on every node and whether zimbra-snmp is installed; upgrade to 10.1.20 or later.
  2. If you cannot patch yet, remove the SNMP package or disable SNMP notifications and restrict SMTP and SNMP access.
  3. Hunt for JSP web shells, unfamiliar systemd services and unexpected SSH activity between mail nodes.
  4. After any suspected compromise, rotate Zimbra authentication and pre-authentication keys and service credentials, not just the software.

Also notable

  • MikroTik RouterOS pre-authentication remote code execution (CVE-2026-84411). CISA's advisory describes a single crafted HTTP request that can give an unauthenticated attacker root; BleepingComputer reports no known exploitation. Reporting varied between RouterOS 7.23 and 7.24 as the fixed version, so check the advisory (ICSA-26-272-06). Source: BleepingComputer
  • Truffle Security finds 543,699 valid credentials in public GitHub repositories. The research reports a median exposure of 784 days and that many live credentials fall in categories GitHub's push protection does not cover. Source: BleepingComputer
  • TeamViewer patches five high-severity flaws. The most serious is an access control bypass in the Full Client and Host software; users are told to move to version 15.82 or later, and no exploitation has been reported. Source: BleepingComputer
  • Phishing campaign targets C-suite executives to steal Microsoft 365 sessions. ANY.RUN analyzed 351 sandbox submissions, 51 percent from the United States, with lures that install legitimate remote-management tools such as ScreenConnect and Action1. Source: The Hacker News

Frequently asked questions

What is CVE-2026-76504?

It is a critical authentication bypass (CVSS 9.8) in Cisco Catalyst SD-WAN Manager. A crafted HTTP request with altered URI encoding can skip an authentication rule and reach the administrative API without credentials. Cisco says it is being exploited and has released fixed versions for each supported release train.

Is there a workaround for the Cisco SD-WAN Manager flaw?

No. Cisco and the reporting sources state that no workaround exists. The advice is to upgrade to a fixed release and, in the meantime, restrict access to the manager from untrusted networks and place it behind a firewall.

Which Zammad versions are affected by the DIVD zero-days?

Per Forkast, CVE-2026-102489 is exploitable in versions 6.3.0 through 6.5.4, and CVE-2026-102490 affects all versions including the latest alpha. DIVD advises upgrading to Zammad 7 or taking instances offline.

How did attackers steal $387.5 million from Bitget?

Bitget and SlowMist say attackers exploited zero-days in two third-party security products, obtained internal credentials, and used a custom tool to forge risk-control parameters and approve fraudulent withdrawals. The vendors have not been named.

Who is affected by the Zimbra CVE-2026-73570 flaw?

Zimbra Collaboration Suite deployments before version 10.1.20 that have the zimbra-snmp package installed and SNMP notifications enabled. CISA has added the flaw to its Known Exploited Vulnerabilities catalog.

What should a CISO do first this week?

Patch or restrict Cisco SD-WAN Manager, check Zimbra for the SNMP condition, and review which security and management consoles can reach critical systems if compromised.

CISO Platform Breach Intelligence Team
Curated by Pritha Aash, Community Head, CISO Platform. Breach Watch is a daily briefing for senior security leaders, built from verified reporting and written for the person who has to decide what the team does about it before lunch.
NETWORK · SHARE · LEARN
Security leaders compare notes on incidents like these every day inside the CISO Platform community. Joining is free.

Related reading from the community: past editions in the Breach Intelligence briefing archive, practitioner material on identity security for security leaders, guidance on third-party and vendor-risk frameworks, and the wider library of frameworks and checklists on CISO Platform.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.
★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion