Cisco has confirmed that attackers are actively exploiting a critical authentication bypass in Catalyst SD-WAN Manager, the console many enterprises use to control their entire SD-WAN fabric.
What happened
The flaw, tracked as CVE-2026-76504, lets a remote attacker with no credentials at all send a specially crafted HTTP request to the Manager's API and be treated as an authenticated administrator. It carries a CVSS score of 9.8 out of 10. The root cause is a URI-encoding handling bug: encoding just one character in the request path is enough to slip past a restriction meant to limit access to a single API endpoint. Because the default admin account holds the netadmin role, a successful request hands the attacker full control of the device.
Cisco's Product Security Incident Response Team says it became aware of active exploitation in September 2026, after the issue surfaced during a routine Technical Assistance Center support case. The advisory does not say how many organizations have been hit, when the activity began, who is behind it, or what attackers did once inside — a reminder that patching alone doesn't tell you whether you were already compromised.
Why it matters
This is the fourth SD-WAN Manager vulnerability Cisco has fixed in 2026, following CVE-2026-20182 in May and CVE-2026-20245 / CVE-2026-20262 in June — and CISA's Known Exploited Vulnerabilities catalog has now logged eight Cisco SD-WAN flaws added this year alone. Critically, the fixed builds that closed those earlier issues do not cover this one: a Manager patched in May or June is still exposed. SD-WAN Manager is typically the single pane of glass for an organization's wide-area network, so a compromised Manager can mean fabric-wide impact rather than a single device.
Who's affected
Every on-prem / self-managed release train earlier than the fixed versions below. Cisco-managed SD-WAN Cloud is already patched (20.15.605) and needs no customer action; Cloud-Hosted environments already carry the mitigation.
| Release train | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
What to do
- Patch now. There is no workaround — upgrade to the fixed release for your train as soon as possible.
- Restrict exposure in the meantime. Keep SD-WAN Manager's admin interfaces (HTTPS/443, SSH/22, NETCONF/830) off the open internet. Allow only known, trusted hosts, and route HTTPS access through a jump host or a dedicated management subnet.
- Hunt before you assume you're clean. Check
/var/log/nms/containers/service-proxy/serviceproxy-access.logand/var/log/nms/vmanage-server.logforj_security_checklogin requests containing encoded characters (e.g.%6a_security_check) from unrecognized IPs, and watch for authentication tied toviptela-reserved-accounts, which should only be used internally by the system. - Preserve evidence before upgrading. Capture an admin-tech diagnostic file from the Manager first — Cisco has previously said that patching alone does not remove an attacker who already gained access.
- If you suspect compromise, open a Severity 3 case with Cisco TAC and reference CVE-2026-76504 in the title.
