Skip to content
TrustList
News

Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being exploited: an authentication bypass with no workaround

Editorial

By TrustList Editorial

Cisco says attackers are exploiting CVE-2026-76504 (CVSS 9.8) in Catalyst SD-WAN Manager, letting an unauthenticated remote attacker reach the API as admin. There is no workaround: upgrade to a fixed release and check the logs.

About Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being exploited: an authentication bypass with no workaround

Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is being exploited: an authentication bypass with no workaround

30 September 2026 — Cisco published a security advisory on 30 September 2026 for CVE-2026-76504, a vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage). The company rates it 9.8 under CVSS. Cisco says that "in September 2026, the Cisco PSIRT became aware of active exploitation" of the flaw, and that "there are no workarounds that address this vulnerability".

What the flaw does

The bug is in the API's session-based authentication. Cisco says requests with improper URI encoding can bypass an authentication rule meant to restrict access to a particular API endpoint. An unauthenticated, remote attacker who sends a crafted HTTP request can therefore reach an affected system with the privileges of the admin user. The advisory says every SD-WAN Manager is affected "regardless of system configuration", and that systems with ports exposed to the internet are at risk. The flaw was found while Cisco was resolving a support case.

Fixed releases

Release train First fixed release
Earlier than 20.9 migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

The Cisco-managed SD-WAN Cloud has been fixed in release 20.15.605, with no customer action needed.

How to check for compromise

Cisco lists indicators of compromise to audit:

  • In /var/log/nms/containers/service-proxy/serviceproxy-access.log, look for requests to j_security_check with an encoded character from unknown IP addresses. Cisco's example is POST /%6a_security_check, and it stresses that any one encoded character can be used.
  • In /var/log/nms/vmanage-server.log, look for the same requests made for users whose names begin with viptela-reserved-.

Customers who find signs of compromise can open a Severity 3 case with Cisco TAC, with the CVE in the title, and attach the output of request admin-tech.

What to do

  • Upgrade every on-premises SD-WAN Manager to the fixed release for its train now; Cisco treats mitigations only as temporary.
  • Until then, restrict access to the Manager from untrusted networks, including the internet, to known hosts, following Cisco's SD-WAN hardening guide.
  • Audit both logs for the indicators above, going back as far as your retention allows.
  • Managed-service providers running SD-WAN for clients should confirm the version on every tenant's Manager.

Sources

Categories & features