Mastodon Mastodon Mastodon Mastodon

Critical vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-76504) is being exploited — patches available

Photo of author

CyberSecureFox Editorial Team

Published:

On 30 September 2026, Cisco published a security advisory about a critical vulnerability CVE-2026-76504 (CVSS 9.8) in Cisco Catalyst SD-WAN Manager — a centralized management platform for SD-WAN networks. The vulnerability allows a remote unauthenticated attacker to gain access to the system’s API with administrator privileges. According to Cisco PSIRT, the vulnerability is already being exploited by threat actors. There are no workarounds — the only way to remediate it is to update to a fixed version. CISA has added the vulnerability to the Known Exploited Vulnerabilities catalog with a remediation deadline of 3 October 2026.

Technical essence of the vulnerability

The vulnerability is classified as CWE-177 — improper handling of URI encoding. It affects the API session management mechanism used by SD-WAN Manager to process user authentication. As follows from the Cisco documentation, the manager uses the /j_security_check endpoint for session-based authentication with issuance of a JSESSIONID.

The crux of the issue: the system incorrectly processes URI encoding of characters in an HTTP request, which makes it possible to bypass an authentication rule that restricts access to a specific API endpoint. In the example from Cisco’s advisory, a single path character is encoded as /%6a_security_check (where %6a is the letter “j”), but any character in the request can be encoded. The attacker does not need credentials — it is enough to be able to send a specially crafted request to the manager’s API.

By default, the administrator account has the netadmin role, which allows all operations on the device. Thus, successful exploitation gives the attacker full control over SD-WAN Manager.

The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration. The risk is especially high for instances that are reachable from the internet.

Affected versions and fixes

Cisco has released fixes for the following branches:

  • Versions earlier than 20.9 — migration to a fixed release is required
  • 20.9 — fixed in 20.9.10.1
  • 20.12 — fixed in 20.12.8.2
  • 20.15 — fixed in 20.15.6.1
  • 20.18 — fixed in 20.18.4.1
  • 26.1 — fixed in 26.1.2.1
  • 26.2 — fixed in 26.2.1

Cisco SD-WAN Cloud (Cisco Managed) has already been fixed in release 20.15.605 — no action is required from users. Importantly, branches 20.10, 20.11, 20.13, 20.14, and 20.16 are not mentioned in the current advisory, although they were referenced in previous ones. SD-WAN Cloud-Pro and SD-WAN for Government (FedRAMP) deployments are also not mentioned.

CVE-2026-76504 is a separate vulnerability from three previously fixed SD-WAN issues: CVE-2026-20182 (CVSS 10.0, fixed in May), CVE-2026-20245 (CVSS 7.8), and CVE-2026-20262 (CVSS 6.5), which were fixed in June. The fixed versions for those vulnerabilities are older than for CVE-2026-76504, so a manager updated only for the May or June fixes remains vulnerable.

Series of SD-WAN vulnerabilities in 2026

CVE-2026-76504 is already the fourth vulnerability in the Cisco SD-WAN product line to be added to the CISA KEV catalog in 2026. All four confirmed entries — CVE-2026-20182, CVE-2026-20245, CVE-2026-20262, and CVE-2026-76504 — affect SD-WAN Manager and Controller components. We have already analyzed the exploitation of earlier vulnerabilities in this line in detail: CVE-2026-20182 in May and CVE-2026-20245 in July. The steady stream of critical vulnerabilities in a single product line points to systemic security problems in the SD-WAN Manager codebase.

Detecting compromise

Cisco describes specific indicators to look for in two log files:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log — entries related to j_security_check from unknown or unauthorized IP addresses
  • /var/log/nms/vmanage-server.log — entries for users with names starting with viptela-reserved- (reserved system service accounts)

Cisco warns that similar entries may also appear during normal system operation. Every match must be correlated with legitimate activity to avoid false positives. In addition, any character in the request path may be encoded — %6a is just one example.

The advisory does not contain ready-made detection rules and does not clarify whether the update removes access for an attacker who has already broken into the system. In the advisories for the May and June vulnerabilities, Cisco explicitly stated that updating alone is not sufficient to remediate a confirmed compromise — first it is necessary to collect an admin-tech file.

Recommendations

Until you update, Cisco recommends the following temporary restrictions:

  • Limit access to SD-WAN Manager from untrusted networks, including the internet
  • Allow connections only from known trusted hosts
  • Place SD-WAN management components behind a firewall

According to the SD-WAN hardening guide, administrative interfaces (ports 443, 22, 830) must not be directly accessible from the internet. HTTPS access to the manager should be allowed only via an intermediate host or management subnet.

To check for possible compromise, Cisco recommends opening a TAC case with Severity 3, specifying CVE-2026-76504 in the title. Before doing this, you must run the request admin-tech command on the manager and prepare the output file for analysis.

Organizations using Cisco Catalyst SD-WAN Manager in their own infrastructure should immediately update the system to a fixed version from the list above. If prompt updating is not possible, isolate the management interface from the internet and check the logs for signs of compromise. If suspicious entries are found, collect admin-tech before updating and contact Cisco TAC, since the update itself may not eliminate the consequences of an intrusion that has already occurred.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.