Cisco patches exploited SD-WAN Manager auth bypass (CVE-2026-76504)
Cisco fixed CVE-2026-76504 (CVSS 9.8), an unauthenticated API auth bypass in Catalyst SD-WAN Manager already exploited in the wild. CISA added it to KEV the same day.
Cisco has patched CVE-2026-76504, a CVSS 9.8 authentication-bypass flaw in Catalyst SD-WAN Manager (formerly vManage) that lets an unauthenticated remote attacker reach an API endpoint and gain administrator-level access. Cisco says it is already exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog the same day.
The primary reference is Cisco's advisory cisco-sa-sdwan-webauth-xr8beuuU, published September 30; the flaw is tracked at CVE-2026-76504 and is now in the CISA KEV catalog.
What the bug does
The flaw is improper handling of URI encoding in an HTTP request (CWE-177) reaching the API session-authentication component j_security_check. By URL-encoding a single character in the request path — for example /%6a_security_check — an attacker bypasses the authentication rule and gains API access with admin privileges. No credentials, no user interaction. Cisco rates it CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
The blast radius is the point. SD-WAN Manager is the control plane for the entire fabric — a single instance can manage up to 6,000 devices — so admin access to the Manager reaches every connected branch.
Affected and fixed versions
The vulnerability affects the product regardless of configuration, and Cisco has published no workaround. Fixed releases:
- 20.9 branch and earlier → 20.9.10.1
- 20.12 → 20.12.8.2
- 20.15 → 20.15.6.1
- 20.18 → 20.18.4.1
- 26.1 → 26.1.2.1
- 26.2 → 26.2.1
Cisco-managed SD-WAN Cloud instances are already fixed (release 20.15.605).
Exploitation status
Confirmed. Cisco's advisory states: "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability." The company says it found the flaw during a Technical Assistance Center support case.
Cisco lists log entries to hunt for compromise. Review these for j_security_check hits — including URI-encoded variants — from unknown IPs:
/var/log/nms/containers/service-proxy/serviceproxy-access.log
/var/log/nms/vmanage-server.log
Action checklist
- Upgrade now to the fixed release for your branch. There is no workaround; patching is the only remediation.
- Pull SD-WAN Manager off the public internet. Instances with the API exposed are the ones being hit — restrict management access to a trusted network or VPN.
- Hunt the logs above for
j_security_checkaccess, especially URL-encoded paths, from IPs you don't recognize. - Assume fabric-wide compromise if you find hits. Admin on the Manager means control of every managed edge device — rotate credentials and review device configs, don't just patch.
Context
This is the second edge-appliance zero-day exploited in the wild that we've covered this week, after Citrix's NetScaler flaws (CVE-2026-88771). Internet-facing management planes — VPN concentrators, SD-WAN controllers, ADCs — remain the softest high-value target on the perimeter: one unauthenticated request against a box that fans out to thousands of devices. The pattern doesn't change; the vendor name does.