Critical Cisco SD-WAN Manager Authentication Bypass Actively Exploited

Summary
Cisco says attackers are exploiting CVE-2026-76504, a critical unauthenticated API bypass in Catalyst SD-WAN Manager. Fixed releases are available; Cisco and Rapid7 urge emergency upgrades and compromise checks.
Key points
- CVE-2026-76504 is a critical URL-encoding flaw (CVSS 9.8) that lets an unauthenticated remote attacker bypass authentication to a specific API endpoint with admin privileges.
- Cisco reported active exploitation beginning in September 2026; internet-exposed Catalyst SD-WAN Manager systems are at risk.
- Cisco released fixed software versions for affected releases; the cloud-based Cisco SD-WAN Cloud Managed release 20.15.605 is also fixed, with no customer action required.
- No workaround is available. Cisco advises restricting access from unsecured networks and limiting any necessary internet access to trusted hosts, while still applying updates.
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 30, with a remediation deadline of October 3, 2026.
- Cisco recommends checking logs for suspicious encoded j_security_check requests and usernames beginning with viptela-reserved-; these indicators may also occur during normal operations.
Article Details
- Vulnerability Types
- API authentication bypass due to improper handling of URL encoding (CWE-177)
- Severity
- Critical; CVSSv3.1 9.8
- Affected Versions
- Cisco Catalyst SD-WAN Software earlier than 20.9
- Cisco Catalyst SD-WAN Software 20.9
- Cisco Catalyst SD-WAN Software 20.12
- Cisco Catalyst SD-WAN Software 20.15
- Cisco Catalyst SD-WAN Software 20.18
- Cisco Catalyst SD-WAN Software 26.1
- Cisco Catalyst SD-WAN Software 26.2
- Exploitation Status
- active
- Exploit Availability
- unknown
- Patch Status
- available
- Workarounds
- No workarounds are available.
- As a temporary mitigation, prevent access to on-premises systems from unsecured networks. If internet access is required, restrict access to known, trusted hosts and protect control components behind a filtering device.
CVE
CVE-2026-20127was also affected by two critical, unauthenticated peering authentication flaws earlier in 2026: CVE-2026-20127 and Rapid7-discovered CVE-2026-20182. Both were distinct issues in the vdaemon service and similarCVE-2026-20182unauthenticated peering authentication flaws earlier in 2026: CVE-2026-20127 and Rapid7-discovered CVE-2026-20182. Both were distinct issues in the vdaemon service and similar parts of its networking stack.CVE-2026-76504On September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8
Vendors
Products
Cisco Catalyst SD-WAN Manageradvisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URLCisco Catalyst SD-WAN SoftwareCisco Catalyst SD-WAN Software releaseCisco SD-WAN CloudCisco has addressed the vulnerability in the cloud-based Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605, and indicates that no customer action is required for that service.