Cisco warns of actively exploited authentication bypass in SD-WAN Manager
TLDR
- Cisco disclosed CVE-2026-76504, a critical (CVSS 9.8) authentication bypass in Catalyst SD-WAN Manager, after its own support team found it was already being exploited.
- A crafted HTTP request lets an unauthenticated attacker use the Manager's API as an admin user, with the netadmin role able to perform any operation on the device.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog on 30 September, giving federal agencies until 3 October to patch.
- It is the fifth SD-WAN zero-day exploited in the wild in 2026, after flaws disclosed in February, May and June; a WatchTowr researcher notes eight 2026 SD-WAN CVEs have now landed on CISA's KEV list.
Update, 1 October, what changed: Cisco confirmed it rolled out fixed releases across every affected branch, with no workaround available in the meantime, and said it became aware of active exploitation in September 2026 while its Technical Assistance Center handled a support case.3 WatchTowr head of threat intelligence Jake Knott said Cisco SD-WAN has become "an ever-present staple" of CISA's KEV catalog, with eight 2026 CVEs landing on the list this year alone, calling it "an extremely clear signal that attackers have recognized the value of the platform."3 Knott recommended organisations hunt for POST requests to URL-encoded variants of /j_security_check and review instances for signs exploitation already occurred.3 Neither Cisco nor CISA has disclosed who is behind the in-the-wild exploitation.3
Cisco's Product Security Incident Response Team said it became aware of active exploitation of CVE-2026-76504 while its Technical Assistance Center was handling a support case.1 The flaw stems from the Manager mishandling URI encoding in an HTTP request, letting a crafted request bypass an authentication rule meant to restrict access to a single API endpoint; because the resulting session carries the admin account's netadmin role, an attacker can "perform all operations on the device."1 The bug affects Catalyst SD-WAN Manager "regardless of how the system is configured," with no other Cisco products listed as affected.1
Cisco rated the flaw CVSS 9.8 and said there is no workaround, publishing fixed releases across every affected train, including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1.2 Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and Cloud Hosted environments already have mitigations applied.1 Administrators are advised to check serviceproxy-access.log and vmanage-server.log for unauthorised j_security_check entries, including requests using the URI-encoded "j" string %6a_security_check, and for suspicious "viptela-reserved-" usernames.2
CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on 30 September, giving federal civilian agencies until 3 October to secure their systems.2 BleepingComputer counted this as the fifth SD-WAN zero-day exploited in the wild in 2026, following CVE-2026-20127 in February, CVE-2026-20182 in May and CVE-2026-20245 and CVE-2026-20262 in June, and noted CISA has tagged 90 Cisco vulnerabilities as exploited since November 2021, including four affecting SD-WAN Manager and seven exploited by ransomware groups.2
Why it matters: this is Cisco's fifth actively exploited SD-WAN zero-day this year, and because the flaw grants full admin control with no workaround available, every unpatched, internet-reachable SD-WAN Manager stays a direct path to total network device takeover until it is upgraded.
Sources
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager (The Hacker News)
- Cisco warns of new SD-WAN zero-day exploited in attacks (BleepingComputer)
- Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability (SecurityWeek)