SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityNetworksAccess management

Cisco sd-wan flaw grants administrator access

Cisco confirms active exploitation of a critical SD-WAN Manager flaw. Review fixed versions, log indicators and urgent response steps.

By Soclyde Team

An empty workstation in a network room while an SD-WAN appliance is checked

In summary

  • Cisco reports active exploitation of CVE-2026-76504 in Catalyst SD-WAN Manager.
  • A crafted HTTP request can bypass authentication and gain administrator privileges.
  • Install a fixed release and review the logs Cisco identifies.

Explore next

Soclyde resources

Article contents

Cisco published a critical advisory on September 30 for Catalyst SD-WAN Manager. Vulnerability CVE-2026-76504 lets an unauthenticated remote attacker bypass an API access-control rule and obtain administrator privileges. Cisco confirms that the flaw is being actively exploited.

An API reachable without authentication

The issue lies in how the product handles encoded characters in a URI. A crafted request can bypass the rule protecting an API endpoint. An attacker does not need a legitimate account first if the vulnerable interface is reachable.

Cisco assigns the flaw a CVSS score of 9.8. It affects Catalyst SD-WAN Manager regardless of configuration. The risk concerns the network management plane: the resulting access has the administrator privileges described by Cisco.

Exploitation has already been reported

Cisco says its incident response team became aware of active exploitation in September. On September 30, CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog; the Canadian Centre for Cyber Security also published an advisory about the issue. Systems with ports exposed to the internet face greater exposure. These reports do not mean every vulnerable deployment has been compromised.

Cisco recommends checking logs for requests to j_security_check containing an encoded character, such as %6a, and usernames beginning with viptela-reserved-. These indicators can also appear during normal activity, so compare them with expected network behavior and source addresses.

Apply the fixed releases

Cisco has issued fixed releases for supported branches. Initial fixed versions include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. For releases earlier than 20.9, Cisco advises migrating to a fixed release branch.

There is no workaround that fixes the vulnerability. For on-premises deployments, Cisco recommends filtering access to control components and allowing only trusted hosts. This reduces exposure but does not replace upgrading. Cisco has applied the fix to its managed SD-WAN cloud service.

Priorities for network teams

Start by inventorying software versions and exposed interfaces, then install the appropriate fixed release. Review service and vManage logs for the relevant period. If indicators align, preserve evidence and contact Cisco TAC with the CVE identifier and the admin-tech file Cisco recommends.

Administrator secrets should be unique and protected, but rotating them does not fix an authentication bypass. Handle the software update, network restriction, log review and administrator-account assessment as separate steps.

How Soclyde fits

Soclyde does not protect Catalyst SD-WAN Manager or remediate this flaw. A password vault can help a team keep unique administrator secrets and organize rotation after an investigation, but it cannot replace software updates or network access controls.

Key points

CVE-2026-76504 is a critical vulnerability with active exploitation confirmed by Cisco. Install a fixed release, limit access to management interfaces and review logs in context. To organize account secrets, see our secure password generator guide.

For handling shared access with clear sharing and revocation rules, see our guide to secure team password sharing.

To discuss managing the relevant access, you can also contact Soclyde.

Frequently asked questions

Which systems are affected by CVE-2026-76504?

Cisco says Catalyst SD-WAN Manager is affected regardless of configuration. Fixed releases depend on the software branch, so check Cisco’s table before scheduling an upgrade.

Is the vulnerability being exploited?

Yes. Cisco says its PSIRT team became aware of active exploitation in September 2026, and CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30. An isolated indicator does not, by itself, prove a system was compromised.

What should administrators do first?

Upgrade to a fixed release and inspect serviceproxy-access.log and vmanage-server.log for the patterns Cisco describes, comparing them with normal activity in your environment.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading