VYPR
kevPublished Sep 30, 2026· 2 sources

Cisco Warns of Active Exploitation of Critical SD-WAN Manager Authentication Bypass

Attackers are actively exploiting CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, allowing unauthenticated remote attackers to gain administrative privileges.

Cisco has issued a stern warning regarding the active exploitation of a critical zero-day vulnerability, identified as CVE-2026-76504, within its Catalyst SD-WAN Manager software. This flaw, which carries a severe CVSS score of 9.8 out of 10, allows unauthenticated remote attackers to bypass security controls and execute API commands with administrative privileges.

The vulnerability resides in the Manager's API component responsible for handling login sessions. Specifically, it stems from an improper handling of URI encoding in HTTP requests. A maliciously crafted request can exploit this weakness to circumvent an authentication rule, granting unauthorized access to a specific API endpoint. This means an attacker needs no credentials whatsoever, only the ability to send the crafted request to the Manager's API, making internet-exposed instances particularly vulnerable.

Once access is gained, attackers can leverage the administrative privileges of the default 'netadmin' role, which is capable of performing all operations on the device. Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation in September 2026, with the vulnerability initially discovered during a support case handled by Cisco's Technical Assistance Center (TAC). The advisory does not specify the number of affected customers, the timeline of the attacks, the identity of the threat actors, or the specific actions taken by compromised systems.

Cisco has released updated versions of the SD-WAN Manager to address this critical flaw. The fixed releases vary depending on the release train, with specific versions provided for 20.9, 20.12, 20.15, 20.18, 26.1, and 26.2. For older release trains, including those earlier than 20.9, customers are advised to migrate to a fixed release. It is important to note that these fixes are distinct from previously disclosed Cisco SD-WAN vulnerabilities patched in May and June of 2026; therefore, systems updated for those earlier flaws still require this latest patch.

For customers using Cisco SD-WAN Cloud Hosted environments, the mitigation is already in place, and no further action is required. However, for on-premises deployments, Cisco strongly advises restricting access to the Manager from unsecured networks, such as the public internet. If internet access is necessary, it should be limited to known, trusted hosts, and control components should be situated behind a firewall. Cisco's hardening guide also recommends that administrative interfaces, typically on ports 443, 22, and 830, should not be directly exposed to the internet.

To detect potential compromise, Cisco recommends monitoring specific log files for unusual "j_security_check" entries originating from unknown or unauthorized IP addresses. These entries might appear in /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log, particularly for users whose names begin with "viptela-reserved-", indicating system service accounts. It's crucial to analyze these logs carefully, as similar entries can occur during normal operation, necessitating a comparison against typical activity to avoid false positives.

CVE-2026-76504 is the latest in a series of Cisco SD-WAN vulnerabilities that have been actively exploited throughout 2026. As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) had already included eight Cisco SD-WAN flaws in its Known Exploited Vulnerabilities (KEV) catalog for the year, underscoring a persistent trend of targeting this critical network management infrastructure.

The new article provides further technical details on CVE-2026-76504, including its root cause as improper handling of URL encoding (CWE-177) and specific log file locations to monitor for indicators of compromise. It also clarifies that Cisco has addressed the vulnerability in cloud-based Cisco SD-WAN Cloud releases and offers no workarounds for on-premises deployments, emphasizing immediate upgrades and system audits.

Synthesized by Vypr AI