Cisco Patches Actively Exploited Catalyst SD-WAN Flaw

Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
Table of Contents
    Add a header to begin generating the table of contents

    Cisco has released patched software for a critical authentication bypass vulnerability in its Catalyst SD-WAN Manager platform that attackers are already exploiting to seize full administrative control of enterprise wide-area network infrastructure. The flaw, tracked as CVE-2026-76504 and rated 9.8 out of 10 on the CVSS severity scale, affects every deployment of the SD-WAN management product — formerly known as SD-WAN vManage — regardless of how an individual instance is configured.

    How CVE-2026-76504 Bypasses Authentication in SD-WAN Manager

    Catalyst SD-WAN Manager is the centralized console administrators use to configure, monitor, and push policy to the branch routers and tunnels that make up a Cisco software-defined WAN deployment. That central role is exactly what makes an authentication bypass in the product itself so consequential: anyone who can reach the management interface without credentials inherits the same oversight a legitimate network administrator would normally have.

    The vulnerability stems from improper handling of URI encoding in HTTP requests processed by Catalyst SD-WAN Manager’s API session-management mechanism. Cisco’s advisory describes an authentication bypass that lets an attacker reach restricted administrative API endpoints without first proving their identity to the system.

    Attackers Use URI-Encoded Characters to Reach Restricted Admin APIs

    Observed exploitation involves crafted HTTP requests that substitute URI-encoded characters — such as “%6a” in place of the letter “j” — to slip past an authentication rule that would otherwise block unauthenticated access. Once the encoded request clears that check, the attacker reaches administrative API endpoints with the same privileges a legitimate administrator would hold. Cisco has confirmed it became aware of active exploitation in the field but has not disclosed the identity or scope of the attackers behind the campaign, nor how many organizations have been affected.

    CISA’s Three-Day Federal Deadline for Catalyst SD-WAN Manager

    The Cybersecurity and Infrastructure Security Agency added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30, giving federal civilian agencies until October 3 to apply the fix — a three-day window that signals how seriously the agency is treating the active exploitation already underway. CISA has also published indicators of compromise and hardening guidance alongside the KEV addition, giving defenders technical detail to hunt for signs of compromise in their own environments.

    Six Fixed Releases Span Current and Legacy SD-WAN Branches

    Cisco has published fixed versions across both its current and legacy maintenance branches: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Organizations running earlier releases must migrate to one of these fixed trains, since no interim patch applies on top of an unpatched build. Cisco-managed cloud deployments of SD-WAN Manager have already been updated on the vendor’s side, but customers running the software on their own infrastructure must apply the update themselves. Critically, Cisco has confirmed no workaround exists — disabling features or restricting network access does not neutralize the authentication bypass, leaving a full software upgrade as the only path to remediation.

    Why a Workaround-Free, Pre-Authentication Flaw Raises the Stakes

    An unauthenticated path to administrative control of SD-WAN management infrastructure is an especially attractive target because a single compromised manager instance can expose visibility and control over the branch routers, tunnels, and policies it orchestrates across an entire enterprise WAN. Security teams have long treated network-management platforms — the systems that configure and monitor other network gear — as high-value targets precisely because compromising one grants control over everything it manages, a pattern that has repeatedly driven urgent patch cycles for edge and management appliances in recent years.

    The absence of any workaround compounds that risk. When a vendor can offer no interim mitigation beyond patching, the time between public disclosure and the point when every exposed instance is updated becomes the period of maximum exposure, and attackers who already have working exploit code have every incentive to expand their targeting during that window. CISA’s three-day remediation deadline for federal agencies, while not binding on private-sector organizations, reflects an assessment that delay carries real operational risk rather than theoretical concern. Enterprises running Catalyst SD-WAN Manager that have not yet confirmed their version against the fixed releases should treat this as an immediate priority rather than part of a routine patch cycle, given that exploitation is already active and the technical bypass method is now public.

    The fact that CVE-2026-76504 applies uniformly across every deployment, regardless of how an organization has configured the product, also removes a common fallback defenders rely on when a flaw is tied to a specific optional feature or setting. There is no configuration choice that reduces exposure here — only the version running on the appliance determines whether it is vulnerable. That uniformity, combined with the absence of a workaround and the active exploitation Cisco has already confirmed, places this disclosure in the category of SD-WAN and VPN-adjacent management-plane flaws that have repeatedly drawn sustained attacker interest once public, since compromising the orchestration layer of a WAN deployment can expose far more than any single branch router would on its own.

    Related Posts