Cisco SD-WAN Authentication Flaw Gives Remote Attackers Full Administrative Access
Cisco warns of CVE-2026-76504, a CVSS 9.8 auth bypass in Catalyst SD-WAN Manager exploited for admin access. See fixes and detection tips.
Illustrative image generated with AI
Cisco has disclosed an actively exploited authentication bypass in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to obtain the privileges of the platform’s administrator account.
Tracked as CVE-2026-76504, the vulnerability carries a CVSS 3.1 score of 9.8. Cisco published its advisory on September 30, 2026 at 13:00 GMT after identifying the issue while its Technical Assistance Center was handling a customer support case.
Cisco’s Product Security Incident Response Team became aware of exploitation during September 2026. The company has not disclosed when the attacks began, how many customers were affected, who conducted them, or what the intruders did after obtaining access.
URI encoding defeats an API authentication rule
CVE-2026-76504 affects session-based authentication for the Cisco Catalyst SD-WAN Manager API. Improper processing of URI-encoded characters lets a crafted HTTP request evade an authentication rule that should restrict access to a specific endpoint.
The attacker does not need credentials, an existing session, or user interaction. Successful exploitation grants the privileges assigned to the admin user.
By default, that account holds the netadmin role, which permits every operation on the device. The vulnerability therefore exposes confidentiality, integrity, and availability, reflected in Cisco’s complete CVSS vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Cisco classifies the underlying weakness as CWE-177 and tracks it internally under bug ID CSCww79570.
The authentication path j_security_check is central to exploitation. Cisco’s example uses the request path:
/%6a_security_check
Here, %6a is the URI-encoded representation of the letter j. However, defenders should not search only for that exact string. Cisco warns that an attacker can encode any single character in the request, creating multiple representations of the same endpoint.
This is an authentication-boundary failure rather than a stolen-password attack. Changing credentials alone does not remove the vulnerable request-processing behavior.
Every configuration is affected, but fixed releases are available
The affected product is Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage. Cisco says the product is vulnerable regardless of configuration, and no other product is listed as affected.
The management platform can control as many as 6,000 SD-WAN devices through one dashboard. Compromise of the Manager can therefore give an attacker a highly privileged position in a large network deployment.
Cisco has released the following fixes:
| Cisco Catalyst SD-WAN release train | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
There is no workaround that corrects the flaw. Cisco strongly recommends installing a fixed version.
The advisory does not list release trains 20.10, 20.11, 20.13, 20.14, or 20.16. Their omission should not be interpreted as confirmation that they are unaffected. Administrators running an unlisted train should consult Cisco’s Upgrade Matrix and confirm the appropriate migration path.
Cisco SD-WAN Cloud (Cisco Managed) was fixed in release 20.15.605 and requires no customer action. Customers can verify their version or remediation status through the service interface’s Help function.
Cisco also says mitigation has already been deployed in Cisco Catalyst SD-WAN Cloud Hosted environments. That deployment model is distinct from the Cisco Managed cloud release fixed in 20.15.605. The current advisory does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), so their status cannot be inferred from the omission.
What defenders should search for
Internet-exposed Managers face the clearest risk. Administrators should review the following files for requests involving j_security_check from unknown or unauthorized addresses:
/var/log/nms/containers/service-proxy/serviceproxy-access.log
/var/log/nms/vmanage-server.log
In vmanage-server.log, defenders should pay particular attention to activity associated with usernames beginning with:
viptela-reserved-
These names belong to reserved system service accounts. Their appearance is not automatically malicious, because legitimate platform activity can generate similar records. Each match must be evaluated against expected operations, source addresses, exposure, and surrounding events.
Cisco’s access-log example, dated September 29, 2026, contains a successful HTTP response to:
POST /%6a_security_check HTTP/1.1
The corresponding example in the vManage log records the encoded path against a user displayed as viptela-reserved-... These are illustrative indicators, not a complete detection rule.
Defenders should normalize URI encoding before matching request paths. A narrow search for %6a_security_check may miss variants that encode a different character.
Organizations that suspect compromise should open a Severity 3 Cisco TAC case and include CVE-2026-76504 in the title. Before opening the case, Cisco instructs customers to run:
request admin-tech
The resulting admin-tech file should be provided to TAC for examination. Cisco has not stated that upgrading will remove an attacker who already obtained access, so suspected incidents require investigation in addition to patching.
Exposure reduction while upgrades are prepared
Until an on-premises Manager can be upgraded, access from the internet and other untrusted networks should be restricted. Where external connectivity is operationally necessary, Cisco recommends allowing only known hosts over the ports and protocols required by its deployment documentation.
SD-WAN control components should sit behind a filtering device, with inbound and outbound communication limited to trusted systems. Cisco says a two-layer firewall design can also prevent end users from reaching the outer demilitarized zone directly.
Administrative services on ports 443, 22, and 830 should not be exposed directly to the internet. HTTPS management access should instead be limited to a jump host or dedicated management subnet.
Cisco reported that these network restrictions succeeded in its test environment, but customers must assess possible effects on functionality and performance. They do not replace the software update.
Additional defensive measures include forwarding logs to an external server, retaining them long enough for incident analysis, changing the default administrator password, and limiting administrative privileges according to operational need. Organizations should create operator accounts for routine administration and use a certificate-authority-issued SSL certificate for SSL/TLS deployments.
Earlier patches do not cover this vulnerability
CVE-2026-76504 is separate from three other Cisco SD-WAN vulnerabilities remediated earlier: CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262.
The fixed releases for those issues predate the versions that correct CVE-2026-76504. A Manager patched only against the earlier vulnerabilities therefore remains exposed to the new authentication bypass.
CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities catalog on May 14, 2026, with a federal remediation deadline of May 17. CVE-2026-20245 entered KEV on June 9 with a June 23 deadline, while CVE-2026-20262 was added on June 15 with remediation due June 29.
A separate information-disclosure issue, CVE-2026-20127, entered KEV on February 25, with a February 27 deadline.
No KEV listing or federal remediation deadline has been reported for CVE-2026-76504. Its confirmed exploitation nevertheless makes the risk operational rather than hypothetical.
The broader Cisco context is also active: CVE-2026-76460, CVE-2026-76461, CVE-2026-20079, CVE-2026-20349, CVE-2026-20316, and CVE-2008-4128 entered KEV during the preceding 90 days. CVE-2026-20316 is flagged for known ransomware use.
For Catalyst SD-WAN Manager operators, the immediate priorities are clear: install the applicable fixed release, remove direct internet exposure, preserve relevant logs, and escalate any suspicious authentication activity to Cisco TAC.
Sources
This article is an original reworking based on the sources below.
- primary sourceCisco PSIRT
- The Hacker News
- BleepingComputer
CVEs covered in this article
- CVE-2026-20079Critical10.0A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability
- CVE-2026-20182Critical10.0May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Contr
- CVE-2026-20127Critical10.0A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and
- CVE-2026-76460Critical10.0A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted reques
- CVE-2026-76461Critical9.8A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email pa
- CVE-2026-76504Critical9.8A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, wh
- CVE-2026-20349High8.6A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi
- CVE-2008-4128High8.1Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alia
- CVE-2026-20245High7.8A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying
- CVE-2026-20262Medium6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate
- CVE-2026-20316Medium5.3A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the pres




