
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability resides in Cisco Catalyst SD-WAN Manager’s session authentication and could allow a remote attacker with no credentials to access the system with administrator-level privileges.
“This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system.” reads the advisory. “A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.”
Cisco said its Product Security Incident Response Team learned that attackers were actively exploiting the flaw in September 2026.
“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” continues the advisory.
Cisco’s Technical Assistance Center (TAC) discovered the issue while investigating a customer support case.
The company did not disclose how many customers were affected, when the attacks started, who was behind them, or what attackers did after gaining access.
Cisco says there is no workaround for the vulnerability. For on-premises deployments, customers should restrict internet access and place SD-WAN control components behind a firewall, allowing traffic only from trusted hosts. The mitigation is already in place for cloud-hosted environments, but customers should assess its impact before deploying it.
Below are the impacted versions:
| Cisco Catalyst SD-WAN Software Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
“Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.”
Internet-exposed Catalyst SD-WAN Manager systems should be checked for signs of compromise, while comparing any findings with normal network activity to avoid false positives. Customers should review the serviceproxy-access.log file at /var/log/nms/containers/service-proxy/serviceproxy-access.log for j_security_check requests coming from unknown or unauthorized IP addresses.
They should also check /var/log/nms/vmanage-server.log for j_security_check requests involving usernames that start with viptela-reserved-. The networking giant notes that the %6a string shown in its example represents the letter j, but any single URL-encoded character could be used in an attack. If a compromise is suspected, customers can contact Cisco TAC by opening a Severity 3 case with CVE-2026-76504 in the title.
Cisco also recommends running the request admin-tech command on the SD-WAN Manager (vManage) and providing the resulting admin-tech file to TAC for analysis.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by October 3rd, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)