Back to Feed
VulnerabilitiesSep 30, 2026

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Cisco warns of active exploitation of critical CVE-2026-76504 in SD-WAN Manager.

Summary

Attackers are actively exploiting a critical zero-day vulnerability, CVE-2026-76504, in Cisco Catalyst SD-WAN Manager. This flaw allows unauthenticated remote attackers to bypass authentication and gain administrative access via the Manager's API. Cisco has released fixed versions and advises restricting internet access to the Manager until patched.

Full text

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Swati KhandelwalSep 30, 2026Vulnerability / Network Security Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager's API that handles login sessions. The Manager mishandles URI encoding in an HTTP request. A crafted request can therefore bypass an authentication rule intended to restrict access to a single API endpoint. The attacker needs no credentials, only the ability to send that request to the Manager's API. Managers exposed to the internet are at risk of compromise, according to Cisco. By default, the admin user holds the netadmin role, which is allowed to perform all operations on the device. Cisco said its Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in September 2026. The flaw was found while Cisco's Technical Assistance Center (TAC) was handling a support case. The advisory does not say how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access. Who Needs to Upgrade The flaw affects SD-WAN Manager regardless of how the system is configured. No other product is listed as affected. These are the first fixed releases for each release train: Release train First fixed release Earlier than 20.9 Migrate to a fixed release 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier: CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June. A comparison of the advisories shows that the fixed releases for those flaws are all older than the ones in the table above. So a Manager last upgraded for the May or June fixes still needs this update. The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list. The advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), two deployment types named in the May and June advisories. Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action. Until an on-prem Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet. Where internet access is required, only known, trusted hosts should be allowed in, and the control components should sit behind a firewall. Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place. The mitigation worked in a test environment, according to Cisco, which advises customers to assess its impact on their own networks before applying it. Cisco's SD-WAN hardening guide says administrative interfaces, such as ports 443, 22 and 830, should not be exposed directly to the internet. HTTPS access to the Manager should come only from a jump host or a management subnet. Checking for Signs of Compromise The signs of compromise Cisco describes involve j_security_check, the request path the Manager uses for session-based logins. In Cisco's example, one character of that path is URI-encoded, giving /%6a_security_check, where %6a stands for the letter j. Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses: File: /var/log/nms/containers/service-proxy/serviceproxy-access.log File: /var/log/nms/vmanage-server.log, in particular entries for users whose names start with viptela-reserved- Names starting with viptela-reserved- belong to reserved system service accounts. Any one character in the request can be encoded, so %6a is only an example. The same entries can also appear during normal operation, and each match has to be checked against normal activity to avoid false positives. To help determine whether a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title. Cisco asks them to run request admin-tech on the Manager first, so the output file can be reviewed. The advisory includes no detection rule and does not say whether upgrading removes an attacker who already has access. Cisco's advisories for the May flaw and the first June flaw said an update alone would not resolve a confirmed compromise. They told customers to collect the admin-tech file before upgrading. CVE-2026-76504 follows a series of Cisco SD-WAN flaws flagged as exploited this year. As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cisco, network security, Vulnerability ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header

Indicators of Compromise

  • cve — CVE-2026-76504

Entities

Cisco Catalyst SD-WAN Manager (product)Cisco (vendor)SD-WAN (technology)