Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco SD-WAN Manager Flaw Exploited by Attackers

Network operations center with router configuration terminal and standard enterprise networking equipment.

"became aware of active exploitation of this vulnerability," Cisco's Product Security Incident Response Team said on September 30, 2026.

CVE-2026-76504: how the authentication bypass works

Cisco warned that CVE-2026-76504 is a critical authentication bypass in Cisco Catalyst SD-WAN Manager that can let a remote attacker use the Manager's API as the admin user without any login credentials. The flaw sits in the Manager's API session handling and stems from mishandled URI encoding in an HTTP request. A crafted request can bypass an authentication rule intended to restrict access to a single API endpoint. The vulnerability carries a CVSS score of 9.8 out of 10.

Who needs to upgrade and what is fixed

Cisco said fixed releases are available and there is no workaround. The advisory stresses the flaw affects SD-WAN Manager regardless of configuration; no other Cisco product was listed as affected. Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605 and customers on that managed cloud need take no action. The advisory also notes that CVE-2026-76504 is separate from three SD-WAN flaws fixed earlier this year—CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June—and that Managers last upgraded to address the May or June fixes still need this update because the present fixed releases are newer.

Detection: logs and indicators to check

Cisco provides concrete places to look for possible compromise tied to the Manager's session-based login path, j_security_check. In the advisory Cisco demonstrates a single character of that path URI-encoded—for example, /%6a_security_check where %6a represents the letter 'j'—but warns any one character in the request can be encoded. Administrators should examine two log files for j_security_check entries from unknown or unauthorized IP addresses:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • /var/log/nms/vmanage-server.log, with attention to entries for usernames beginning with viptela-reserved- (reserved system service accounts)

Cisco cautions these same entries can appear during normal operation and that each match must be checked against expected activity to avoid false positives. To aid investigations, Cisco asks customers to open a Severity 3 case with Cisco TAC, include CVE-2026-76504 in the title, and run request admin-tech on the Manager first so the output file can be reviewed. The advisory includes no detection rule and does not say whether upgrading removes an attacker who already has access; Cisco's May and the first June advisories previously warned that an update alone would not resolve a confirmed compromise and recommended collecting the admin-tech file before upgrading.

Interim mitigations for on‑prem Managers and cloud-hosted environments

While fixed releases exist, Cisco advises restricting access to on-prem Managers from unsecured networks such as the internet until systems are upgraded. Where internet access is required, customers should allow only known, trusted hosts and place control components behind a firewall. Cisco's SD‑WAN hardening guide—cited in the advisory—recommends administrative interfaces (notably ports 443, 22 and 830) not be exposed directly to the internet and that HTTPS access to the Manager should come only from a jump host or a management subnet. Cisco Catalyst SD‑WAN Cloud Hosted environments already have the mitigation in place, and Cisco reported the mitigation worked in a test environment, while urging customers to assess its impact on their own networks before applying it.

What this means for security teams, procurement leaders, and regulators

  • Security teams and technologists: Verify whether your Manager is on-premise or Cisco SD‑WAN Cloud (release 20.15.605), apply the fixed release for your train, and search the specified logs for encoded j_security_check requests. If you suspect compromise, follow Cisco's step to open a Severity 3 TAC case and gather the admin-tech output before upgrading.
  • Procurement and operations leaders: Confirm which release train your deployed Managers are on. Managers upgraded for the May or June fixes still require this update because the new fixed releases postdate those earlier patches.
  • Regulators and infrastructure operators: Note this vulnerability is one in a string of SD‑WAN issues tracked this year; as of September 30, the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog listed eight Cisco SD‑WAN flaws added in 2026.

Cisco's advisory is specific about the mechanism and the short list of mitigations available while patches are applied, but it does not disclose how many customers were affected, when the attacks began, who carried them out, or what actions attackers took after gaining access. For any organization running a Cisco Catalyst SD‑WAN Manager exposed to the internet, the advisory makes clear the immediate choices are to patch promptly or to strictly limit remote access until the patch is applied.

Source: The Hacker News — Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager