Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild
Cisco warns CVE-2026-76504, a critical SD-WAN Manager auth bypass, is being actively exploited.
Cisco disclosed CVE-2026-76504, a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager's API session authentication caused by improper handling of URI encoding. An unauthenticated remote attacker can send a crafted request using encoded characters against the j_security_check endpoint and obtain administrator API access. Cisco said it became aware of active exploitation in September 2026 and published advisory cisco-sa-sdwan-webauth-xr8beuuU on September 30. No complete workaround exists; fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1, while cloud-hosted environments are already mitigated.
- CVE-2026-76504 scores CVSS 9.8 and needs no authentication.
- URI encoding bypasses a rule protecting the j_security_check API.
- Successful attacks yield administrator privileges on SD-WAN Manager.
- Cisco confirmed active exploitation during September 2026.
- Patches span 20.9.10.1 through 26.2.1; cloud hosts are already fixed.
Vulnerabilities mentionedAll →
- CVE-2026-765049.82%Unauthenticated admin API auth bypass in Cisco Catalyst SD-WAN Managerpublished · Cisco Catalyst SD-WAN Manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 20.12.8.2 | possible. Cisco has released patches in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cisco SD-WAN C |
| ipv4 | 20.15.6.1 | isco has released patches in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cisco SD-WAN Cloud Manage |
| ipv4 | 20.18.4.1 | leased patches in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cisco SD-WAN Cloud Managed Release 2 |
| ipv4 | 20.9.10.1 | as soon as possible. Cisco has released patches in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cis |
| ipv4 | 26.1.2.1 | hes in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cisco SD-WAN Cloud Managed Release 20.15.605 a |
Full article461 words · extracted from cybersecuritynews.com · click to collapse
Cisco has disclosed a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that attackers are actively exploiting.
The flaw, tracked as CVE-2026-76504, could allow an unauthenticated remote attacker to gain administrative access to vulnerable SD-WAN management systems. The vulnerability received a CVSS score of 9.8 and affects Cisco Catalyst SD-WAN Manager regardless of its system configuration.
CVE-2026-76504 exists in the API session-based authentication management component of Cisco Catalyst SD-WAN Manager. The issue results from improper handling of URI encoding in HTTP requests.
An attacker can send a specially crafted request to the exposed API and bypass an authentication rule intended to protect a specific endpoint.
Successful exploitation allows the attacker to access the API with administrator-level privileges. This could give an intruder control over a high-value SD-WAN management platform, potentially enabling network configuration changes, access to connected infrastructure, and further compromise of enterprise environments.
Cisco SD-WAN Manager 0-Day Vulnerability Exploited
Cisco said attackers can abuse encoded characters in requests to the j_security_check endpoint. The company provided an example involving the encoded character %6a, which represents the letter “j”: POST /%6a_security_check HTTP/1.1
Cisco noted that %6a is only one example. Any single character encoded in the request could potentially trigger the authentication bypass.
Administrators should immediately investigate Cisco Catalyst SD-WAN Manager logs for suspicious access attempts. Cisco specifically recommends reviewing the serviceproxy-access.log file at /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests involving j_security_check from unfamiliar or unauthorized IP addresses.
Security teams should also inspect /var/log/nms/vmanage-server.log for requests to encoded j_security_check paths associated with usernames beginning with viptela-reserved-. These are system service accounts, and suspicious requests involving such accounts may indicate attempted or successful exploitation.
No workarounds fully address the flaw. For on-premises deployments, Cisco recommends restricting SD-WAN Manager access from the public internet, permitting access only from known and trusted hosts, and placing SD-WAN control components behind filtering devices such as firewalls.
Cisco published the advisory( cisco-sa-sdwan-webauth-xr8beuuU ) on September 30, 2026. The company confirmed it became aware of active exploitation in September and strongly urged organizations to apply software updates.
Cisco SD-WAN Cloud Hosted environments already have this mitigation deployed. Organizations should upgrade to fixed releases as soon as possible. Cisco has released patches in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.
Cisco SD-WAN Cloud Managed Release 20.15.605 also fixes the issue, with no customer action required. Cisco customers who suspect compromise should collect an admin-tech file using the request admin-tech command and open a Severity 3 TAC case referencing CVE-2026-76504.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.