Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
At a glance
- Severity
- CriticalCVSS 9.8
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-76504
- Vendors and products
- Cisco
- Reported by
- 1 outlet
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.
The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager's API that handles login sessions.
The Manager mishandles URI encoding in an HTTP request. A crafted request can therefore bypass an authentication rule intended to restrict access to a single API endpoint.
The attacker needs no credentials, only the ability to send that request to the Manager's API. Managers exposed to the internet are at risk of compromise, according to Cisco. By default, the admin user holds the netadmin role, which is allowed to perform all operations on the device.
Cisco said its Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in September 2026. The flaw was found while Cisco's Technical Assistance Center (TAC) was handling a support case.
The advisory does not say how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access.
Who Needs to Upgrade
The flaw affects SD-WAN Manager regardless of how the system is configured. No other product is listed as affected. These are the first fixed releases for each release train:
| Release train | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier: CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June.
A comparison of the advisories shows that the fixed releases for those flaws are all older than the ones in the table above. So a Manager last upgraded for the May or June fixes still needs this update.
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list. The advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), two deployment types named in the May and June advisories.
Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action. Until an on-prem Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet. Where internet access is required, only known, trusted hosts should be allowed in, and the control components should sit behind a firewall.
Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place. The mitigation worked in a test environment, according to Cisco, which advises customers to assess its impact on their own networks before applying it.
Cisco's SD-WAN hardening guide says administrative interfaces, such as ports 443, 22 and 830, should not be exposed directly to the internet. HTTPS access to the Manager should come only from a jump host or a management subnet.
Checking for Signs of Compromise
The signs of compromise Cisco describes involve j_security_check, the request path the Manager uses for session-based logins. In Cisco's example, one character of that path is URI-encoded, giving /%6a_security_check, where %6a stands for the letter j.
Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses:
- File: /var/log/nms/containers/service-proxy/serviceproxy-access.log
- File: /var/log/nms/vmanage-server.log, in particular entries for users whose names start with viptela-reserved-
Names starting with viptela-reserved- belong to reserved system service accounts.
Any one character in the request can be encoded, so %6a is only an example. The same entries can also appear during normal operation, and each match has to be checked against normal activity to avoid false positives.
To help determine whether a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title. Cisco asks them to run request admin-tech on the Manager first, so the output file can be reviewed.
The advisory includes no detection rule and does not say whether upgrading removes an attacker who already has access. Cisco's advisories for the May flaw and the first June flaw said an update alone would not resolve a confirmed compromise. They told customers to collect the admin-tech file before upgrading.
CVE-2026-76504 follows a series of Cisco SD-WAN flaws flagged as exploited this year. As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026.
Originally published by The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
Vulnerabilities referenced
- CVE-2026-765049.8Critical
Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Used in attacksAdded to CISA's list 2026-09-30
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-76504 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-30 15:24 UTC
Related stories
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
The Hacker News · 2026-10-01 · exploited
- Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
The Hacker News · 2026-10-01
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
The Hacker News · 2026-10-01
- DIVD says Zammad zero-days enabled AI-driven network breach
BleepingComputer · 2026-09-30
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
The Hacker News · 2026-09-30 · exploited