Cisco SD-WAN Authentication Flaw Gives Remote Attackers Full Administrative Access

Cisco warns of CVE-2026-76504, a CVSS 9.8 auth bypass in Catalyst SD-WAN Manager exploited for admin access. See fixes and detection tips.

Cisco SD-WAN Authentication Flaw Gives Remote Attackers Full Administrative Access
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

Cisco has disclosed an actively exploited authentication bypass in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to obtain the privileges of the platform’s administrator account.

Tracked as CVE-2026-76504, the vulnerability carries a CVSS 3.1 score of 9.8. Cisco published its advisory on September 30, 2026 at 13:00 GMT after identifying the issue while its Technical Assistance Center was handling a customer support case.

Cisco’s Product Security Incident Response Team became aware of exploitation during September 2026. The company has not disclosed when the attacks began, how many customers were affected, who conducted them, or what the intruders did after obtaining access.

URI encoding defeats an API authentication rule

CVE-2026-76504 affects session-based authentication for the Cisco Catalyst SD-WAN Manager API. Improper processing of URI-encoded characters lets a crafted HTTP request evade an authentication rule that should restrict access to a specific endpoint.

The attacker does not need credentials, an existing session, or user interaction. Successful exploitation grants the privileges assigned to the admin user.

By default, that account holds the netadmin role, which permits every operation on the device. The vulnerability therefore exposes confidentiality, integrity, and availability, reflected in Cisco’s complete CVSS vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X

Cisco classifies the underlying weakness as CWE-177 and tracks it internally under bug ID CSCww79570.

The authentication path j_security_check is central to exploitation. Cisco’s example uses the request path:

/%6a_security_check

Here, %6a is the URI-encoded representation of the letter j. However, defenders should not search only for that exact string. Cisco warns that an attacker can encode any single character in the request, creating multiple representations of the same endpoint.

This is an authentication-boundary failure rather than a stolen-password attack. Changing credentials alone does not remove the vulnerable request-processing behavior.

Every configuration is affected, but fixed releases are available

The affected product is Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage. Cisco says the product is vulnerable regardless of configuration, and no other product is listed as affected.

The management platform can control as many as 6,000 SD-WAN devices through one dashboard. Compromise of the Manager can therefore give an attacker a highly privileged position in a large network deployment.

Cisco has released the following fixes:

Cisco Catalyst SD-WAN release train First fixed release
Earlier than 20.9 Migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

There is no workaround that corrects the flaw. Cisco strongly recommends installing a fixed version.

The advisory does not list release trains 20.10, 20.11, 20.13, 20.14, or 20.16. Their omission should not be interpreted as confirmation that they are unaffected. Administrators running an unlisted train should consult Cisco’s Upgrade Matrix and confirm the appropriate migration path.

Cisco SD-WAN Cloud (Cisco Managed) was fixed in release 20.15.605 and requires no customer action. Customers can verify their version or remediation status through the service interface’s Help function.

Cisco also says mitigation has already been deployed in Cisco Catalyst SD-WAN Cloud Hosted environments. That deployment model is distinct from the Cisco Managed cloud release fixed in 20.15.605. The current advisory does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), so their status cannot be inferred from the omission.

What defenders should search for

Internet-exposed Managers face the clearest risk. Administrators should review the following files for requests involving j_security_check from unknown or unauthorized addresses:

/var/log/nms/containers/service-proxy/serviceproxy-access.log
/var/log/nms/vmanage-server.log

In vmanage-server.log, defenders should pay particular attention to activity associated with usernames beginning with:

viptela-reserved-

These names belong to reserved system service accounts. Their appearance is not automatically malicious, because legitimate platform activity can generate similar records. Each match must be evaluated against expected operations, source addresses, exposure, and surrounding events.

Cisco’s access-log example, dated September 29, 2026, contains a successful HTTP response to:

POST /%6a_security_check HTTP/1.1

The corresponding example in the vManage log records the encoded path against a user displayed as viptela-reserved-... These are illustrative indicators, not a complete detection rule.

Defenders should normalize URI encoding before matching request paths. A narrow search for %6a_security_check may miss variants that encode a different character.

Organizations that suspect compromise should open a Severity 3 Cisco TAC case and include CVE-2026-76504 in the title. Before opening the case, Cisco instructs customers to run:

request admin-tech

The resulting admin-tech file should be provided to TAC for examination. Cisco has not stated that upgrading will remove an attacker who already obtained access, so suspected incidents require investigation in addition to patching.

Exposure reduction while upgrades are prepared

Until an on-premises Manager can be upgraded, access from the internet and other untrusted networks should be restricted. Where external connectivity is operationally necessary, Cisco recommends allowing only known hosts over the ports and protocols required by its deployment documentation.

SD-WAN control components should sit behind a filtering device, with inbound and outbound communication limited to trusted systems. Cisco says a two-layer firewall design can also prevent end users from reaching the outer demilitarized zone directly.

Administrative services on ports 443, 22, and 830 should not be exposed directly to the internet. HTTPS management access should instead be limited to a jump host or dedicated management subnet.

Cisco reported that these network restrictions succeeded in its test environment, but customers must assess possible effects on functionality and performance. They do not replace the software update.

Additional defensive measures include forwarding logs to an external server, retaining them long enough for incident analysis, changing the default administrator password, and limiting administrative privileges according to operational need. Organizations should create operator accounts for routine administration and use a certificate-authority-issued SSL certificate for SSL/TLS deployments.

Earlier patches do not cover this vulnerability

CVE-2026-76504 is separate from three other Cisco SD-WAN vulnerabilities remediated earlier: CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262.

The fixed releases for those issues predate the versions that correct CVE-2026-76504. A Manager patched only against the earlier vulnerabilities therefore remains exposed to the new authentication bypass.

CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities catalog on May 14, 2026, with a federal remediation deadline of May 17. CVE-2026-20245 entered KEV on June 9 with a June 23 deadline, while CVE-2026-20262 was added on June 15 with remediation due June 29.

A separate information-disclosure issue, CVE-2026-20127, entered KEV on February 25, with a February 27 deadline.

No KEV listing or federal remediation deadline has been reported for CVE-2026-76504. Its confirmed exploitation nevertheless makes the risk operational rather than hypothetical.

The broader Cisco context is also active: CVE-2026-76460, CVE-2026-76461, CVE-2026-20079, CVE-2026-20349, CVE-2026-20316, and CVE-2008-4128 entered KEV during the preceding 90 days. CVE-2026-20316 is flagged for known ransomware use.

For Catalyst SD-WAN Manager operators, the immediate priorities are clear: install the applicable fixed release, remove direct internet exposure, preserve relevant logs, and escalate any suspicious authentication activity to Cisco TAC.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →