Cisco SD-WAN Manager zero-day CVE-2026-76504 exploited, added to CISA KEV

Cisco warned that attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager that grants admin access; CISA ordered federal agencies to patch by 3 October.

Cisco SD-WAN Manager zero-day CVE-2026-76504 exploited, added to CISA KEV

At a glance

  • CVE-2026-76504 (CVSS 9.8) lets unauthenticated remote attackers gain admin privileges on Catalyst SD-WAN Manager via crafted HTTP requests.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on 30 September with a 3 October deadline for federal agencies.
  • Fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1.
  • Admins should review service-proxy and vmanage-server logs for suspicious j_security_check requests.

Cisco has warned that attackers are exploiting a critical zero-day authentication bypass in Catalyst SD-WAN Manager, formerly known as vManage, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on 30 September 2026. Tracked as CVE-2026-76504 with a CVSS score of 9.8, the bug allows an unauthenticated, remote attacker to access an affected system with administrator privileges, according to The Hacker News.

What happened

According to BleepingComputer, Cisco confirmed in September that the vulnerability was being exploited in attacks. CISA's KEV listing gives Federal Civilian Executive Branch agencies until 3 October 2026 to apply fixes, an unusually short window that reflects the severity of the issue.

The Hacker News reports that no details have been disclosed about who is behind the attacks, how many organizations have been compromised, or when exploitation began.

BleepingComputer notes this is the fifth actively exploited SD-WAN zero-day of 2026. Jake Knott of watchTowr told The Hacker News that Cisco SD-WAN "feels like an ever-present staple" of the KEV list, with eight Cisco SD-WAN CVEs added to the catalog this year.

Technical details

Cisco says the vulnerability exists in the API session-based authentication management of SD-WAN Manager. According to the advisory quoted by BleepingComputer, it is caused by improper handling of URI encoding in an HTTP request, which allows a request to bypass an authentication rule meant to restrict API access. A successful attacker can interact with the API as an administrator without valid credentials.

BleepingComputer reports that threat actors have been observed using URI-encoded characters in malicious requests targeting the login endpoint.

Who is affected

All supported Catalyst SD-WAN Manager release trains are affected. According to BleepingComputer, Cisco has released the following fixes:

  • releases earlier than 20.9: migrate to a fixed release
  • 20.9.x: fixed in 20.9.10.1
  • 20.12.x: fixed in 20.12.8.2
  • 20.15.x: fixed in 20.15.6.1
  • 20.18.x: fixed in 20.18.4.1
  • 26.1.x: fixed in 26.1.2.1
  • 26.2.x: fixed in 26.2.1

Because SD-WAN Manager centrally controls an organization's wide area network, administrative access can give attackers a powerful foothold over network configuration across branch sites.

What to do

Organizations should upgrade to a fixed release immediately. Cisco and the reporting outlets recommend reviewing logs for signs of compromise, specifically:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • /var/log/nms/vmanage-server.log

According to The Hacker News, defenders should look for POST requests to j_security_check (including URL-encoded variants) originating from unknown IP addresses, as well as activity involving usernames beginning with viptela-reserved-. Management interfaces should not be exposed to the internet and should be restricted to trusted administrative networks.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.