Full Report
Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. CVE-2026-76504 carries a
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Manager Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-76504
- **CVSS Score:** 9.8 (Critical)
- **CWE:** Not explicitly stated (Likely CWE-288: Authentication Bypass Using an Alternate Path or Channel / CWE-115: Misinterpretation of Input)
## Affected Systems
- **Products:** Cisco Catalyst SD-WAN Manager (formerly vManage)
- **Versions:**
- Versions earlier than 20.9
- 20.9 (versions prior to 20.9.10.1)
- 20.12 (versions prior to 20.12.8.2)
- 20.15 (versions prior to 20.15.6.1)
- 20.18 (versions prior to 20.18.4.1)
- 26.1 (versions prior to 26.1.2.1)
- 26.2 (versions prior to 26.2.1)
- **Configurations:** All configurations are affected if the Manager’s API is reachable.
## Vulnerability Description
The vulnerability exists in the API login session handler of the Cisco Catalyst SD-WAN Manager. The system mishandles URI encoding within HTTP requests. An unauthenticated remote attacker can submit a specially crafted request containing URI-encoded characters (e.g., encoding 'j' as `%6a`) to bypass authentication rules. This allows the attacker to access restricted API endpoints and gain administrative privileges (the `netadmin` role) without providing credentials.
## Exploitation
- **Status:** **Exploited in the wild** (Active exploitation reported as of September 2026).
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Full access to management data and network configurations)
- **Integrity:** High (Ability to perform all operations on the device as a network administrator)
- **Availability:** High (Potential for full device takeover or disruption of SD-WAN management)
## Remediation
### Patches
Cisco has released the following fixed versions. Users are urged to migrate to these release trains:
- **20.9.10.1**
- **20.12.8.2**
- **20.15.6.1**
- **20.18.4.1**
- **26.1.2.1**
- **26.2.1**
- *Note: Cisco SD-WAN Cloud (Cisco Managed) is already patched (20.15.605).*
### Workarounds
There are **no direct workarounds** that resolve the flaw. Mitigation strategies include:
- Restricting access to the Manager from unsecured networks (Internet).
- Implementing IP-based Access Control Lists (ACLs) to allow only trusted hosts/subnets.
- Ensuring administrative interfaces (Ports 443, 22, 830) are behind a firewall or jump host.
## Detection
### Indicators of Compromise
Search for URI-encoded variations of the authentication path `j_security_check` (e.g., `%6a_security_check`) in the following logs:
- `/var/log/nms/containers/service-proxy/serviceproxy-access.log`
- `/var/log/nms/vmanage-server.log`
### Detection methods and tools
- Monitor logs for unauthorized or unknown IP addresses attempting to access the paths above.
- Specifically inspect log entries for users with names starting with `viptela-reserved-`, which belong to reserved system service accounts.
## References
- **Vendor Advisory:** hxxps://sec.cloudapps.cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
- **News Source:** hxxps://thehackernews[.]com/2026/09/cisco-warns-of-attackers-exploiting.html