SShortSingh.
Back to feed

Cisco warns of actively exploited zero-day in SD-WAN Manager API

0
·1 views

Cisco disclosed on September 30 that attackers are actively exploiting a critical zero-day vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager. The flaw, which has a CVSS score of 9.8, allows an unauthenticated attacker with network access to the Manager's API to gain full administrative privileges. Cisco has released patched software versions for several release trains but states there are no workarounds, advising customers to restrict network access until systems are upgraded. The vulnerability affects all on-premises deployments of the software, particularly those exposed to the internet, regardless of their configuration.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Check URLs for personal data before sharing publicly, developer guide advises

A technical draft from the 주소나와 team outlines a JavaScript function to inspect URLs before adding them to public link collections. The function parses URL strings without making external requests to check for potentially sensitive data like email addresses, tokens, or user-specific parameters. This is a pre-sharing review step, distinct from checking link accessibility or page content, focusing on data that might be exposed in browser history or logs. The guide emphasizes that automated checks are not a safety guarantee and must be followed by human review for final sharing decisions.

0
ProgrammingDEV Community ·

Kubernetes probes and experiment signals require distinct monitoring approach

Node.js applications on Kubernetes require separate monitoring of startup, liveness, and readiness probes alongside experimental cohort outcomes. Platform teams should manage container lifecycle probes while experiment owners define rollback thresholds based on user experience metrics. Container health does not guarantee experiment success, as instances can pass probes while users in specific cohorts encounter failures. Effective monitoring should distinguish between temporary dependency issues requiring patience and actual treatment breaches requiring intervention. This separation prevents unnecessary rollbacks and restart storms while maintaining service reliability.

0
ProgrammingDEV Community ·

Palantir's 'Forward Deployed Engineer' term now describes multiple distinct roles and products

The term 'Forward Deployed Engineer' has evolved to describe different positions and products across the tech industry. Palantir originally created the role to combine on-site environment learning with software development. The company has now released an AI-powered product called 'AI FDE' designed to operate its Foundry platform through conversational commands. This expansion of the term creates potential confusion and scoping problems for projects. The AI product currently handles platform operations but does not replace the core human functions of the original role.

0
ProgrammingDEV Community ·

AI researchers find Claude's performance declines as conversation context grows

Developers have observed that Anthropic's Claude AI shows declining performance as conversation context expands over time. The model operates most effectively at the start of interactions when context is minimal and condensed. Unlike humans, Claude has no memory between requests and must re-process the entire conversation history with each new message. This leads to attention dilution, especially when context contains corrections or stale information. Researchers recommend starting new sessions for distinct topics to maintain optimal performance.