Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.

The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager’s API as the admin user. Fixed releases are available, and there is no workaround.

CVE-2026-76504 carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager’s API that handles login sessions.

The Manager mishandles URI encoding in an HTTP request. A crafted request can therefore bypass an authentication rule intended to restrict access to a single API endpoint.

The attacker needs no credentials, only the ability to send that request to the Manager’s API. Managers exposed to the internet are at risk of compromise, according to Cisco.

By default, the admin user holds the netadmin role, which is allowed to perform all operations on the device.

Cybersecurity

Cisco said its Product Security Incident Response Team “became aware of active exploitation of this vulnerability” in September 2026. The flaw was found while Cisco’s Technical Assistance Center (TAC) was handling a support case.

The advisory does not say how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access.

Who Needs to Upgrade

The flaw affects SD-WAN Manager regardless of how the system is configured. No other product is listed as affected. These are the first fixed releases for each release train:

Release train First fixed release
Earlier than 20.9 Migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

CVE-2026-76504 is separate from three Cisco SD-WAN flaws fixed earlier: CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June.

A comparison of the advisories shows that the fixed releases for those flaws are all older than the ones in the table above. So a Manager last upgraded for the May or June fixes still needs this update.

The table does not list the 20.10, 20.11, 20.13, 20.14, or 20.16 release trains, which Cisco’s May advisory did list. The advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), two deployment types named in the May and June advisories.

Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action.

Until an on-prem Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet. Where internet access is required, only known, trusted hosts should be allowed in, and the control components should sit behind a firewall.

Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place. The mitigation worked in a test environment, according to Cisco, which advises customers to assess its impact on their own networks before applying it.

Cybersecurity

Cisco’s SD-WAN hardening guide says administrative interfaces, such as ports 443, 22 and 830, should not be exposed directly to the internet. HTTPS access to the Manager should come only from a jump host or a management subnet.

Checking for Signs of Compromise

The signs of compromise Cisco describes involve j_security_check, the request path the Manager uses for session-based logins. In Cisco’s example, one character of that path is URI-encoded, giving /%6a_security_check, where %6a stands for the letter j.

Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses:

  • File: /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • File: /var/log/nms/vmanage-server.log, in particular entries for users whose names start with viptela-reserved-

Names starting with viptela-reserved- belong to reserved system service accounts.

Any one character in the request can be encoded, so %6a is only an example. The same entries can also appear during normal operation, and each match has to be checked against normal activity to avoid false positives.

To help determine whether a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title. Cisco asks them to run request admin-tech on the Manager first, so the output file can be reviewed.

The advisory includes no detection rule and does not say whether upgrading removes an attacker who already has access. Cisco’s advisories for the May flaw and the first June flaw said an update alone would not resolve a confirmed compromise. They told customers to collect the admin-tech file before upgrading.

CVE-2026-76504 follows a series of Cisco SD-WAN flaws flagged as exploited this year. As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here