
Cisco: Attackers Exploit Critical Authentication Bypass in SD-WAN Manager
Cisco says attackers are actively exploiting CVE-2026-76504, a 9.8-rated authentication bypass in Cisco Catalyst SD-WAN Manager. Fixed releases are out, there is no workaround, and internet-exposed systems are at risk.
Cisco warned on September 30 that attackers are actively exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the platform organizations use to manage their SD-WAN networks. It carries a CVSS score of 9.8 out of 10 and is tracked as CVE-2026-76504. Fixed releases are available, and there is no workaround.
What the flaw allows
The flaw sits in the part of the Manager's API that handles login sessions. Cisco says the Manager mishandles URI encoding in an HTTP request, so a crafted request can bypass an authentication rule meant to restrict access to a single API endpoint. No credentials are needed, only the ability to reach the API. By default the admin user holds the netadmin role, which may perform all operations on the device. Internet-exposed Managers are at risk of compromise.
Cisco's Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in September 2026, and the flaw was found while its Technical Assistance Center (TAC) handled a support case. The advisory does not say how many customers were attacked, when the attacks began, or who carried them out.
Who needs to upgrade
The flaw affects SD-WAN Manager regardless of configuration, and no other product is listed as affected. The first fixed releases are 20.9.10.1 (20.9), 20.12.8.2 (20.12), 20.15.6.1 (20.15), 20.18.4.1 (20.18), 26.1.2.1 (26.1) and 26.2.1 (26.2); anything older than 20.9 must migrate to a fixed release. CVE-2026-76504 is separate from three earlier SD-WAN flaws (CVE-2026-20182 in May, CVE-2026-20245 and CVE-2026-20262 in June). Because those fixes are older, a Manager last patched in May or June still needs this update. Cisco SD-WAN Cloud (Cisco Managed) is already fixed in 20.15.605.
Mitigation and signs of compromise
Until an on-premises Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet. Where internet access is required, only trusted hosts should be allowed in and control components should sit behind a firewall. The hardening guide says administrative interfaces (ports 443, 22 and 830) should not be exposed to the internet, and HTTPS access should come only from a jump host or a management subnet.
Cisco points to j_security_check, the request path used for session-based logins. In its example one character is URI-encoded, giving /%6a_security_check, where %6a stands for j. Administrators should look for j_security_check entries from unknown IP addresses in /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log, especially entries for user names starting with viptela-reserved-. A suspected compromise can be reported to Cisco TAC as a Severity 3 case, with CVE-2026-76504 in the title.
The advisory has no detection rule. As of September 30, CISA's Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.