Cisco Catalyst SD-WAN Manager
Cisco dropped an advisory on September 30, and the news is not good, because attackers are actively exploiting a critical zero-day in Catalyst SD-WAN Manager, which is the system companies use to manage their Cisco SD-WAN networks.
The flaw is CVE-2026-76504, and it carries a CVSS score of 9.8 out of 10, which means a remote attacker with no login access can use the Manager's API as the admin user, and fixed releases are available, but there is no workaround.
The vulnerability sits in the part of the Manager's API that handles login sessions, and Cisco explains that the Manager mishandles URI encoding in an HTTP request, so a crafted request can bypass an authentication rule intended to restrict access to a single API endpoint.
The attacker needs no credentials, only the ability to send that request to the Manager's API, and Managers exposed to the internet are at risk of compromise, according to Cisco, and by default, the admin user holds the netadmin role, which is allowed to perform all operations on the device.
Quick Summary
|
What |
Details |
|
Vulnerability |
CVE-2026-76504 |
|
CVSS |
9.8 |
|
Affected Product |
Cisco Catalyst SD-WAN Manager |
|
Impact |
Unauthenticated API access as admin |
|
Workaround |
None |
|
Status |
Actively exploited |
Cisco Confirms Active Exploitation
Cisco said its Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2026, and the flaw was found while Cisco's Technical Assistance Center was handling a support case.
The advisory does not say how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access, so the public picture is incomplete.
Who Needs to Upgrade
The flaw affects SD-WAN Manager regardless of how the system is configured, and no other product is listed as affected, and these are the first fixed releases for each release train.
|
Release Train |
First Fixed Release |
|
Earlier than 20.9 |
Migrate to a fixed release |
|
20.9 |
20.9.10.1 |
|
20.12 |
20.12.8.2 |
|
20.15 |
20.15.6.1 |
|
20.18 |
20.18.4.1 |
|
26.1 |
26.1.2.1 |
|
26.2 |
26.2.1 |
CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier, which are CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June, and a comparison of the advisories shows that the fixed releases for those flaws are all older than the ones in the table above, so a Manager last upgraded for the May or June fixes still needs this update.
The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco's May advisory did list, and the advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government, two deployment types named in the May and June advisories.
Cisco SD-WAN Cloud, which is Cisco Managed, is already fixed in release 20.15.605, and customers on it need to take no action.
What to Do Until You Can Patch
Until an on-prem Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet, and where internet access is required, only known and trusted hosts should be allowed in, and the control components should sit behind a firewall.
Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place, and the mitigation worked in a test environment, according to Cisco, which advises customers to assess its impact on their own networks before applying it.
Cisco's SD-WAN hardening guide says administrative interfaces, such as ports 443, 22 and 830, should not be exposed directly to the internet, and HTTPS access to the Manager should come only from a jump host or a management subnet.
Checking for Signs of Compromise
The signs of compromise Cisco describes involve j_security_check, which is the request path the Manager uses for session-based logins, and in Cisco's example, one character of that path is URI-encoded, giving /%6a_security_check, where %6a stands for the letter j.
Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses, and they are /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log, with particular attention to entries for users whose names start with viptela-reserved-.
Names starting with viptela-reserved- belong to reserved system service accounts, and any one character in the request can be encoded, so %6a is only an example, and the same entries can also appear during normal operation, so each match has to be checked against normal activity to avoid false positives.
To help determine whether a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title, and Cisco asks them to run request admin-tech on the Manager first, so the output file can be reviewed.
The advisory includes no detection rule and does not say whether upgrading removes an attacker who already has access, and Cisco's advisories for the May flaw and the first June flaw said an update alone would not resolve a confirmed compromise, and they told customers to collect the admin-tech file before upgrading.
CVE-2026-76504 follows a series of Cisco SD-WAN flaws flagged as exploited this year, and as of September 30, the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026.
The Bottom Line
Cisco Catalyst SD-WAN Manager has a critical zero-day that allows unauthenticated API access as admin, and attackers are already exploiting it, so if you run an on-prem Manager, patch to the fixed release for your train, restrict internet exposure in the meantime, and check the two log files for the encoded j_security_check pattern, because an update alone may not remove an attacker who already has access.
Quick Reference
|
Key Point |
Detail |
|
Flaw |
CVE-2026-76504 |
|
CVSS |
9.8 |
|
Impact |
Unauthenticated admin API access |
|
Fixed Releases |
20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 |
|
Workaround |
None |
|
Log Files |
serviceproxy-access.log, vmanage-server.log |
|
Indicator |
j_security_check with URI encoding |
What to Do
- Patch to the fixed release for your train
- Restrict access from unsecured networks
- Use a jump host or management subnet for HTTPS
- Check serviceproxy-access.log and vmanage-server.log
- Look for viptela-reserved- users
- Open a Severity 3 case with Cisco TAC if needed
- Collect admin-tech before upgrading
FAQ Section
What is CVE-2026-76504?
It is a critical zero-day in Cisco Catalyst SD-WAN Manager that allows a remote attacker with no login access to use the Manager's API as the admin user, and it carries a CVSS score of 9.8.
Is there a workaround?
No, there is no workaround, and Cisco advises restricting access to the Manager from unsecured networks until you can patch.
Which releases are fixed?
The first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1, and releases earlier than 20.9 should migrate to a fixed release.
How do I check for compromise?
Look for j_security_check entries with URI encoding in serviceproxy-access.log and vmanage-server.log, especially for users starting with viptela-reserved-, and open a Severity 3 case with Cisco TAC if needed.
Does patching remove an attacker who already has access?
Cisco's advisory does not say, but its advisories for earlier flaws said an update alone would not resolve a confirmed compromise, so you should collect admin-tech before upgrading and assume compromise until proven otherwise.
Is this related to other Cisco SD-WAN flaws?
No, it is separate from CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262, and the fixed releases for those flaws are older than the ones needed for this vulnerability.