Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco says attackers are actively exploiting a critical authentication bypass in Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-76504. Administrators should identify their release, restrict management access from untrusted networks while preparing an upgrade, and review Cisco’s specified logs for suspicious activity. Cisco has not published a victim count or identified an attacker.

What the vulnerability does

CVE-2026-76504 affects Cisco Catalyst SD-WAN Manager. Cisco describes an improper handling of URI encoding in an HTTP request: a crafted request can bypass an authentication rule for an API endpoint and obtain API access with administrator privileges without authenticating. Cisco says the flaw affects the product regardless of system configuration.

Cisco assigns the vulnerability a CVSS 3.1 base score of 9.8, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That score describes severity, not the number of victims or attacks. Cisco’s Product Security Incident Response Team said it became aware of exploitation in September 2026. The Canadian Centre for Cyber Security reported that CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 30, 2026. Neither source quantifies victims or names an attacker. Cisco’s security advisory | Canadian Centre for Cyber Security alert

Is your Cisco SD-WAN Manager affected?

Establish whether your organization runs Cisco Catalyst SD-WAN Manager, then check its exact version and release train against Cisco’s fixed releases. Versions earlier than the applicable threshold are affected; installations earlier than 20.9 must migrate to a fixed release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Release train First fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

For Cisco SD-WAN Cloud (Cisco Managed), Cisco says the issue was addressed in Release 20.15.605 and no user action is required. Customers can check the service version or remediation status through the GUI’s Help function. These thresholds and cloud-service details are from Cisco’s advisory; the Canadian Centre for Cyber Security also summarizes the affected-version thresholds in its alert.

What to do now

  1. Confirm product, hosting, and version. Determine whether the deployment is Catalyst SD-WAN Manager on premises or Cisco-managed cloud, and record its release train and exact version.
  2. Check exposure. Determine whether management access is reachable from the public internet or another untrusted network.
  3. Restrict untrusted access while planning the upgrade. For on-premises deployments, Cisco’s temporary mitigation is to block access from unsecured networks and allow only known, trusted hosts on required ports and protocols. Cisco says this mitigation is deployed in its cloud-hosted environments.
  4. Upgrade to the fixed release for your train. Cisco identifies upgrading as the permanent remediation; use the version thresholds above.
  5. Review logs and escalate suspicious findings. If compromise is uncertain, follow Cisco’s TAC guidance below.

Cisco says there is no workaround that fixes the vulnerability. Filtering is a temporary mitigation, not a patch. Network filtering or access changes can affect functionality or performance, so assess their impact in your environment before applying them. See Cisco’s advisory for its mitigation guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to check for possible exploitation

Review the log locations Cisco identifies

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • /var/log/nms/vmanage-server.log

Look for unusual requests, not just matching strings

Cisco advises looking for requests related to j_security_check from unknown or unauthorized IP addresses. Its examples include encoded URI characters and, in one case, account names beginning with viptela-reserved-. Cisco cautions that indicators can also appear during normal operations. Compare any matches with the system’s usual network posture and activity; a matching string alone does not establish compromise.

Escalate suspected compromise

For compromise assessment, Cisco advises collecting an admin-tech file and opening a Severity 3 TAC case with CVE-2026-76504 in the case title. Use Cisco TAC or your contracted maintenance provider for support. The log paths, indicator cautions, and escalation steps are in Cisco’s advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Cisco Meraki MX68CW-HW Wireless LTE Security SD-WAN Appliance (Renewed)
  • Renewed Enterprise Appliance: This Cisco Meraki MX68CW-HW comes professionally renewed to deliver reliable performance for small to medium-sized business networks, offering enterprise-grade security and SD-WAN capabilities at an accessible price point
  • Integrated Wireless Connectivity: Features built-in wireless capabilities that enable seamless network deployment without requiring additional access points, providing flexible connectivity options for your business environment
  • LTE Failover Support: Equipped with LTE cellular connectivity to ensure continuous network uptime by automatically switching to cellular backup when primary internet connections fail, maintaining business continuity during outages
  • Advanced Security Features: Delivers comprehensive network security with integrated firewall, content filtering, and intrusion detection capabilities to protect your business from cyber threats and unauthorized access
  • SD-WAN Technology: Incorporates software-defined wide area networking functionality that intelligently routes traffic across multiple connections, optimizing application performance and reducing bandwidth costs while simplifying network management

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.