Skip to content
Threat Feed
critical threat exploited

Active Exploitation of Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)

Attackers are actively exploiting an unauthenticated API authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager to gain administrative control via URL-encoded HTTP requests.

CVE search metadata

CVE search record: CVE-2026-76504. Severity: critical. CVSS: 9.8. KEV: no. Product: Catalyst SD-WAN Manager, Cisco SD-WAN Cloud (< 20.15.605). Brief: Active Exploitation of Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/

CVE search record: CVE-2026-20127. Severity: critical. CVSS: 10.0. EPSS: 88.48%. KEV: no. Product: Catalyst SD-WAN Manager, Cisco SD-WAN Cloud (< 20.15.605). Brief: Active Exploitation of Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/

CVE search record: CVE-2026-20182. Severity: critical. CVSS: 10.0. EPSS: 91.52%. KEV: no. Product: Catalyst SD-WAN Manager, Cisco SD-WAN Cloud (< 20.15.605). Brief: Active Exploitation of Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/

What's new

  • 1. added coverage for Catalyst SD-WAN Manager Sep 30, 19:39 via cisa

Cisco has disclosed a critical authentication bypass vulnerability, identified as CVE-2026-76504, affecting Cisco Catalyst SD-WAN Manager. The flaw stems from improper handling of URL encoding (CWE-177) within API authentication logic. An unauthenticated, remote attacker can leverage this weakness to bypass authentication rules by sending crafted HTTP requests to specific API endpoints, granting them unauthorized access with administrative privileges.

Cisco PSIRT has confirmed that this vulnerability is being actively exploited in the wild as of September 2026. This follows other significant authentication bypass flaws discovered in the Catalyst SD-WAN networking stack earlier in the year (CVE-2026-20127 and CVE-2026-20182). Given the critical nature of the flaw and confirmed in-the-wild exploitation, organizations must treat this as an emergency remediation event. There are no workarounds, and all internet-facing instances are at high risk of compromise. Immediate application of vendor-supplied patches is required to secure the control plane.

Attack Chain

  1. Attacker performs reconnaissance to identify internet-facing Cisco Catalyst SD-WAN Manager instances.
  2. Attacker crafts an HTTP request targeting the j_security_check API endpoint.
  3. Attacker applies URI encoding to one or more characters within the request path (e.g., %6a instead of j) to bypass static authentication filters.
  4. The SD-WAN Manager improperly processes the encoded URL, incorrectly validating the request as authenticated.
  5. Attacker gains session access with the privileges of the admin user.
  6. Attacker leverages the administrative session to perform unauthorized configuration changes or exfiltration.
  7. Attacker maintains persistence or executes further commands via the compromised management interface.

Impact

Successful exploitation allows an unauthenticated remote attacker to gain administrative access to the Cisco Catalyst SD-WAN Manager. This impact is severe, potentially resulting in full compromise of the SD-WAN controller, unauthorized access to sensitive network configuration data, or the ability to manipulate global routing and traffic flow across the managed SD-WAN network.

Recommendation

  • Immediately upgrade all on-premises instances of Cisco Catalyst SD-WAN Manager to the fixed releases specified in the Cisco security advisory (e.g., 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1).
  • Deploy the Sigma rules below to monitor for exploitation attempts targeting the j_security_check endpoint.
  • Audit logs located at /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for indicators of anomalous j_security_check access or unexpected usernames prefixed with 'viptela-reserved-'.
  • Restrict access to the SD-WAN management interface to trusted internal IP addresses and protect control components behind network filtering devices.