Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being exploited: an authentication bypass with no workaround
EditorialBy TrustList Editorial
Cisco says attackers are exploiting CVE-2026-76504 (CVSS 9.8) in Catalyst SD-WAN Manager, letting an unauthenticated remote attacker reach the API as admin. There is no workaround: upgrade to a fixed release and check the logs.
- United States
- San Jose, Ca
- Cybersecurity
- Network Security
- +2 more
About Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being exploited: an authentication bypass with no workaround
Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being exploited: an authentication bypass with no workaround
30 September 2026 — Cisco published a security advisory on 30 September 2026 for CVE-2026-76504, a vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage). The company rates it 9.8 under CVSS. Cisco says that "in September 2026, the Cisco PSIRT became aware of active exploitation" of the flaw, and that "there are no workarounds that address this vulnerability".
What the flaw does
The bug is in the API's session-based authentication. Cisco says requests with improper URI encoding can bypass an authentication rule meant to restrict access to a particular API endpoint. An unauthenticated, remote attacker who sends a crafted HTTP request can therefore reach an affected system with the privileges of the admin user. The advisory says every SD-WAN Manager is affected "regardless of system configuration", and that systems with ports exposed to the internet are at risk. The flaw was found while Cisco was resolving a support case.
Fixed releases
| Release train | First fixed release |
|---|---|
| Earlier than 20.9 | migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
The Cisco-managed SD-WAN Cloud has been fixed in release 20.15.605, with no customer action needed.
How to check for compromise
Cisco lists indicators of compromise to audit:
- In /var/log/nms/containers/service-proxy/serviceproxy-access.log, look for requests to j_security_check with an encoded character from unknown IP addresses. Cisco's example is
POST /%6a_security_check, and it stresses that any one encoded character can be used. - In /var/log/nms/vmanage-server.log, look for the same requests made for users whose names begin with
viptela-reserved-.
Customers who find signs of compromise can open a Severity 3 case with Cisco TAC, with the CVE in the title, and attach the output of request admin-tech.
What to do
- Upgrade every on-premises SD-WAN Manager to the fixed release for its train now; Cisco treats mitigations only as temporary.
- Until then, restrict access to the Manager from untrusted networks, including the internet, to known hosts, following Cisco's SD-WAN hardening guide.
- Audit both logs for the indicators above, going back as far as your retention allows.
- Managed-service providers running SD-WAN for clients should confirm the version on every tenant's Manager.
Sources
Categories & features
- United States
- San Jose, Ca
- Cybersecurity
- Network Security
- Vulnerability Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.