TL;DR
Cisco has patched CVE-2026-76504, a CVSS 9.8 authentication bypass in Cisco SD-WAN Manager. Attackers already exploit the flaw in the wild to gain admin access to the API. No workarounds exist, so upgrading is the only real fix.
- CVE: CVE-2026-76504
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Cisco Catalyst SD-WAN Manager
- Affected: 18.3.6, 18.3.7, 18.3.8, 17.2.10, 18.3.6.1, 18.2.0 (+17 more)
- Impact: Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
- Status: Exploited in the wild
- Action: See vendor advisory
Turn Cisco CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
Cisco confirms the attacks are real and recent. The advisory states: “In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.”
The stakes are high. Cisco SD-WAN Manager controls the whole SD-WAN fabric. BleepingComputer notes that one instance can manage up to 6,000 devices. As a result, admin access to the Manager can reach every connected branch.
How the Attack Works
The bug sits in the API session-based authentication logic. Cisco traces it to “improper handling of URI encoding in an HTTP request.” Because of this, a crafted request slips past a rule meant to guard a specific API endpoint. The attacker needs no credentials and no user interaction. In the end, they reach the API with admin privileges.
Affected Versions
The flaw affects Cisco SD-WAN Manager “regardless of system configuration.” Cisco lists these first fixed releases:
- Earlier than 20.9: migrate to a fixed release
- 20.9: 20.9.10.1
- 20.12: 20.12.8.2
- 20.15: 20.15.6.1
- 20.18: 20.18.4.1
- 26.1: 26.1.2.1
- 26.2: 26.2.1
Cisco already fixed its managed cloud service in Release 20.15.605. Those customers need to take no action.
Patch and Mitigation Steps
Upgrade First
Admins should move to a fixed release now, as the Cisco security advisory urges. Meanwhile, on-prem teams should block internet access to the Manager. Only trusted hosts should pass through the firewall.
Hunt for Compromise
Next, review serviceproxy-access.log and vmanage-server.log. Look for j_security_check requests from unknown IP addresses. Also flag entries tied to accounts whose names start with viptela-reserved-. Before you upgrade, run request admin-tech to preserve evidence. Then open a Severity 3 TAC case if anything looks suspicious.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!