VMTech
Discuss a project →

CISA lists actively exploited Cisco SD-WAN Manager auth bypass

CISA lists actively exploited Cisco SD-WAN Manager auth bypass

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-76504, a critical authentication-bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of 9.8 and has been exploited in the wild, prompting CISA to require Federal Civilian Executive Branch agencies to apply fixes by October 3, 2026.

Cisco said it became aware of active exploitation in September 2026. The company has not disclosed who is behind the activity, how many organizations may have been affected, when exploitation first began, or further technical details about the campaigns.

API access as an administrator

CISA describes CVE-2026-76504 as a hex-encoding vulnerability caused by improper handling of URI encoding in an HTTP request. A remote attacker does not need to authenticate to exploit it. By sending a crafted request to an affected system's API, the attacker could bypass authentication and access the API with the privileges of the administrator user.

Catalyst SD-WAN Manager is used to manage, configure and monitor enterprise networks through a central interface. That role makes successful compromise especially consequential: the vulnerable management plane can provide privileged access to the API rather than only to an individual network device.

What defenders should investigate

Cisco has published indicators that customers can use when reviewing their environments. Administrators should audit /var/log/nms/containers/service-proxy/serviceproxy-access.log for entries related to j_security_check originating from unknown or unauthorized IP addresses.

They should also inspect /var/log/nms/vmanage-server.log for j_security_check activity from unknown or unauthorized addresses, particularly calls involving usernames that begin with viptela-reserved-. Cisco further recommends hunting for POST requests to URL-encoded variants of /j_security_check and reviewing those requests for evidence of exploitation.

A repeated target for attackers

The addition extends a wider run of Cisco SD-WAN issues reaching the KEV catalog. As recurring Cisco vulnerability activity documents recurring Cisco vulnerability activity, the latest entry reinforces the operational importance of monitoring internet-facing network-management systems and applying vendor fixes promptly.

Jake Knott, head of threat intelligence at watchTowr, said eight Cisco SD-WAN CVEs had entered KEV during 2026. He characterized the platform as an attractive target because enterprises use it as a single pane of glass for managing large networks.

Organizations operating Cisco Catalyst SD-WAN Manager should upgrade to a fixed release as soon as possible, follow Cisco's vendor guidance, and examine the specified logs and request patterns for signs of attempted or successful authentication bypass. The immediate business implication is to treat the management platform as a high-priority remediation and investigation target while validating that its API has not been accessed through the bypass.

#cybersecurity#cisco#vulnerability#networksecurity
Open analytics
On the site 2 views
min read 3 01.10.2026
Instagram

CISA lists actively exploited Cisco SD-WAN Manager auth bypass

Open the post on Instagram ↗