Critical Cisco SD-WAN Manager Authentication Bypass Actively Exploited

· Original article ↗

Summary

Cisco says attackers are exploiting CVE-2026-76504, a critical unauthenticated API bypass in Catalyst SD-WAN Manager. Fixed releases are available; Cisco and Rapid7 urge emergency upgrades and compromise checks.

Key points

  • CVE-2026-76504 is a critical URL-encoding flaw (CVSS 9.8) that lets an unauthenticated remote attacker bypass authentication to a specific API endpoint with admin privileges.
  • Cisco reported active exploitation beginning in September 2026; internet-exposed Catalyst SD-WAN Manager systems are at risk.
  • Cisco released fixed software versions for affected releases; the cloud-based Cisco SD-WAN Cloud Managed release 20.15.605 is also fixed, with no customer action required.
  • No workaround is available. Cisco advises restricting access from unsecured networks and limiting any necessary internet access to trusted hosts, while still applying updates.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 30, with a remediation deadline of October 3, 2026.
  • Cisco recommends checking logs for suspicious encoded j_security_check requests and usernames beginning with viptela-reserved-; these indicators may also occur during normal operations.

Article Details

Vulnerability Types
  • API authentication bypass due to improper handling of URL encoding (CWE-177)
Severity
Critical; CVSSv3.1 9.8
Affected Versions
  • Cisco Catalyst SD-WAN Software earlier than 20.9
  • Cisco Catalyst SD-WAN Software 20.9
  • Cisco Catalyst SD-WAN Software 20.12
  • Cisco Catalyst SD-WAN Software 20.15
  • Cisco Catalyst SD-WAN Software 20.18
  • Cisco Catalyst SD-WAN Software 26.1
  • Cisco Catalyst SD-WAN Software 26.2
Exploitation Status
active
Exploit Availability
unknown
Patch Status
available
Workarounds
  • No workarounds are available.
  • As a temporary mitigation, prevent access to on-premises systems from unsecured networks. If internet access is required, restrict access to known, trusted hosts and protect control components behind a filtering device.

CVE

Vendors

Products

Countries

Related Articles