VMTech
Discuss a project →

Cisco urges urgent updates for exploited SD-WAN Manager flaw

Cisco urges urgent updates for exploited SD-WAN Manager flaw

Cisco has warned that attackers are actively exploiting CVE-2026-76504, a critical authentication-bypass vulnerability in Cisco Catalyst SD-WAN Manager. The issue has a CVSS score of 9.8 and can allow a remote, unauthenticated attacker to access the Manager API as the admin user.

The vulnerability affects SD-WAN Manager regardless of configuration. Cisco said its Product Security Incident Response Team became aware of active exploitation in September 2026 after its Technical Assistance Center investigated a support case. The company did not disclose the number of affected customers, the attackers' identity, the start of the activity, or what actions may have followed access.

URI encoding bypasses an API authentication control

CVE-2026-76504 lies in the API code that processes login sessions. Improper handling of URI encoding in an HTTP request enables a crafted request to bypass an authentication rule intended to protect one API endpoint. An attacker requires no valid credentials, but must be able to send the request to the Manager API.

The potential impact is substantial because the default admin account has the netadmin role, which Cisco says can perform all operations on the device. Cisco specifically identified internet-exposed Managers as being at risk of compromise. The broader pattern of exploited Cisco issues is also reflected in Cisco vulnerabilities in a wider threat roundup and its account of Cisco vulnerabilities within a wider threat roundup.

Fixed releases and access restrictions

Cisco has released fixes and states that no workaround exists. The first fixed versions are 20.9.10.1 for the 20.9 train, 20.12.8.2 for 20.12, 20.15.6.1 for 20.15, 20.18.4.1 for 20.18, 26.1.2.1 for 26.1, and 26.2.1 for 26.2. Deployments earlier than 20.9 must migrate to a fixed release.

A Manager upgraded for Cisco SD-WAN vulnerabilities fixed in May or June 2026 still requires this update: the releases listed for CVE-2026-76504 are newer. Cisco SD-WAN Cloud, Cisco Managed, is already fixed in release 20.15.605 and requires no customer action. Cisco Catalyst SD-WAN Cloud Hosted environments already have the recommended mitigation in place.

Before an on-premises Manager is upgraded, Cisco recommends limiting access from unsecured networks, including the internet. Where external access is necessary, organizations should permit only known, trusted hosts and place control components behind a firewall. Cisco notes that this mitigation worked in a test environment and advises customers to assess the effect in their own networks.

Reviewing logs for compromise evidence

Cisco recommends checking for requests to j_security_check from unknown or unauthorized IP addresses. One example is /%6a_security_check, where the encoded character represents the letter j, but any character in the path can be encoded. Relevant records are stored in /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log, especially activity involving usernames beginning with viptela-reserved-.

Those entries can occur during normal operations, so each match must be compared with expected activity to avoid false positives. Cisco asks customers seeking compromise assessment to open a Severity 3 TAC case mentioning CVE-2026-76504 and to run request admin-tech on the Manager before submitting the output for review.

For security teams, the immediate business implication is to identify every on-premises SD-WAN Manager, restrict its administrative exposure, preserve diagnostic evidence where suspicious activity is found, and apply the matching fixed release without assuming earlier 2026 patches are sufficient.

#cisco#sdwan#cybersecurity#vulnerability
Open analytics
On the site 1 views
min read 4 30.09.2026
Instagram

Cisco urges urgent updates for exploited SD-WAN Manager flaw

Open the post on Instagram ↗