Back to Newsroom
Threat Intel

CISA Adds Actively Exploited Cisco SD-WAN Manager Bug to KEV Catalog

A critical authentication bypass in Cisco's Catalyst SD-WAN Manager is being exploited in the wild, pushing CISA to set a tight patch deadline for federal agencies.

CISA Adds Actively Exploited Cisco SD-WAN Manager Bug to KEV Catalog

Lead

U.S. authorities have confirmed active, in-the-wild exploitation of a critical flaw in Cisco's Catalyst SD-WAN Manager, adding it to the Known Exploited Vulnerabilities (KEV) catalog and giving federal agencies a hard deadline to patch.

What happened

The flaw, tracked as CVE-2026-76504 and rated 9.8 out of 10 on the CVSS scale, stems from how SD-WAN Manager handles hex-encoded URIs in HTTP requests. An unauthenticated attacker who sends a specially crafted request can slip past the login process entirely and reach the management API with full administrator rights — no credentials required.

Cisco says it first became aware of exploitation attempts in September 2026 but has not disclosed who is behind the activity, how many organizations have been affected, or when the earliest attacks began. The company has published indicators of compromise that defenders can use to check their own environments, pointing to unusual authentication log entries tied to accounts with a "viptela-reserved-" naming pattern — a legacy artifact of Cisco's SD-WAN platform (formerly Viptela).

With the vulnerability now on CISA's KEV list, U.S. Federal Civilian Executive Branch agencies have until October 3, 2026 to apply the fix.

Why it matters

SD-WAN Manager isn't just another appliance — it's the control plane that lets enterprises configure, monitor, and push policy to every site on their network from one place. A successful compromise doesn't hand an attacker one machine; it hands them visibility and control over the whole network fabric behind it. That "single pane of glass" design is exactly what makes it worth targeting, and Cisco's SD-WAN stack has now had eight CVEs added to KEV in 2026 alone — a pattern that shows no sign of slowing.

What to do

  • Patch immediately. Organizations running Catalyst SD-WAN Manager should move to a fixed release without delay — this is an unauthenticated, remote, admin-level bypass with no workaround substitute for patching.
  • Hunt for exploitation. Review access and authentication logs for POST requests to URL-encoded variants of /j_security_check, and check for session or account activity tied to unexpected or unauthorized source IPs.
  • Watch for the "viptela-reserved-" pattern. Unexpected logins or sessions using that naming convention are a strong signal of attempted or successful exploitation.
  • Don't wait for breach confirmation. Given the lack of public detail on the scope of active exploitation, treat internet-facing SD-WAN Manager instances as already-targeted until proven otherwise.
SHARE