Urgent awareness alert. This is awareness content, not a monitored threat intelligence service: always check vendor advisories against your own environment.
On 30 September 2026, Cisco disclosed a critical authentication bypass in Cisco Catalyst SD-WAN Manager (CVE-2026-76504, CVSS 9.8) and confirmed that it is being exploited in the wild. The flaw lies in how the product handles URL encoding in HTTP requests: an unauthenticated, remote attacker can send a crafted request that bypasses an authentication rule and gains administrator-level access to the API. Cisco says systems are vulnerable regardless of configuration, and there is no workaround. The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalogue the same day. Any organisation that manages its wide area network with Cisco SD-WAN, whether on premises or through a managed service provider, should treat this as urgent.
What to do:
- Upgrade SD-WAN Manager to a fixed release: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Releases earlier than 20.9 must migrate to a fixed release. Cisco has fixed its SD-WAN Cloud service in release 20.15.605.
- Check for compromise: review the SD-WAN Manager logs for unusual requests to j_security_check from unknown IP addresses, and for unexpected activity by accounts whose names begin with “viptela-reserved-“.
- Restrict exposure: make sure the management interface cannot be reached from the internet, and allow access only from trusted hosts behind a firewall.
- If a provider manages your SD-WAN, ask them to confirm the fix has been applied.
Source: Cisco security advisory: Cisco Catalyst SD-WAN Manager API authentication bypass vulnerability
If you would like help assessing your exposure, contact us.