0 Comments

If your organization runs Cisco Catalyst SD-WAN Manager — the console that pushes policy and config to every edge router across your wide-area network — stop what you’re doing and check your version. Cisco has confirmed a critical, actively exploited API authentication bypass in that exact product: CVE-2026-76504, CVSS 9.8. It is the fifth Cisco SD-WAN zero-day exploited in the wild this year, and attackers don’t need a single credential to take over the box that controls your entire network.

What the vulnerability is

CVE-2026-76504 is an unauthenticated API authentication bypass in Cisco Catalyst SD-WAN Manager (formerly vManage), the central management console for Cisco’s software-defined wide-area network solution. The flaw lives in how the product handles URI encoding in HTTP requests. A crafted request with an encoded character in the path can slip past the authentication rule meant to gate a specific API endpoint — and land with the privileges of the admin user.

Cisco’s own advisory is blunt: “improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint.” An attacker who can reach the web interface sends one request and gets admin-level API access to the device that controls routing, security policy, and software distribution for the entire SD-WAN fabric.

Why it matters

This is not a cosmetic flaw. SD-WAN Manager is the single plane of glass for your wide-area network. Admin access to it means attackers can read network configuration, pivot into connected management infrastructure, push malicious config to edge routers, disrupt connectivity, or use it as a launching pad for deeper movement into your corporate network. Because the compromise is at the management layer, it can be stealthy — defenders may not notice until well after the attacker has mapped and controlled the environment.

Cisco PSIRT became aware of active exploitation in September 2026 while resolving a TAC support case. On September 30, CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog based on that evidence and ordered US federal civilian agencies to remediate by October 3, 2026 and run a compromise assessment. That is a three-day deadline. If it’s urgent enough for the federal government to move that fast, it’s urgent for you.

Affected versions

The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of configuration. The releases and their fixed builds:

  • Earlier than 20.9 — no fix; migrate to a supported release
  • 20.9 — fixed in 20.9.10.1
  • 20.12 — fixed in 20.12.8.2
  • 20.15 — fixed in 20.15.6.1
  • 20.18 — fixed in 20.18.4.1
  • 26.1 — fixed in 26.1.2.1
  • 26.2 — fixed in 26.2.1

Cloud-hosted Cisco SD-WAN Cloud (Cisco Managed) is fixed in release 20.15.605 with no customer action required. There are no workarounds for the vulnerability — patching or migrating is the only fix.

IOCs and what to look for

Cisco provided indicators of compromise for defenders. On the SD-WAN Manager, run request admin-tech via the vManage CLI to pull an admin-tech file and review it for signs of compromise. Watch for anomalous requests to the management API — especially URIs containing hex-encoded characters targeting restricted endpoints — and any unexpected admin-level activity or new accounts. If you have any doubt, open a Cisco TAC case as Severity 3 titled with CVE-2026-76504 and provide the admin-tech file for review.

What you should do right now

  • Patch immediately. Upgrade to the fixed release listed above for your train. Do not wait for a routine maintenance window — treat this as an emergency, outside your normal patch cycle.
  • Migrate if you’re below 20.9. There is no fix for older releases; move to a supported train now.
  • Lock down reachability. The flaw is unauthenticated and needs no feature flag — reachability to the web interface (TCP 443/8443) is the whole precondition. Restrict access so SD-WAN Manager is reachable only from management segments, never the internet or user VLANs.
  • Run a compromise assessment. If your instance is or was internet-facing, look for evidence of exploitation before you assume patching is enough. Check admin-tech logs, API access logs, and account changes.
  • Compare against KEV. Add CVE-2026-76504 to your vulnerability management queue and track it to closure regardless of your compliance obligations.

Actively exploited, unauthenticated, CVSS 9.8, no workaround, and it manages your entire WAN. The math is simple: patch this one on an emergency basis before it becomes your incident of the week.

Leave a Reply

Related Posts