Cisco SD-WAN Manager Auth Bypass Exploited, With No Workaround
Security / news
Cisco SD-WAN Manager Auth Bypass Exploited, With No Workaround
CVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.

An unauthenticated remote attacker who can reach the API of Cisco Catalyst SD-WAN Manager can send one crafted HTTP request and obtain administrator access, and Cisco says attackers are already doing it. The flaw is CVE-2026-76504, rated 9.8 out of 10 on the CVSS severity scale.
Rapid7's analysis dates Cisco's advisory to Sept. 30, and says CISA put the flaw in its Known Exploited Vulnerabilities catalog the same day with a federal remediation due date of Oct. 3. Cisco has published no workaround.
What the flaw is
The Manager mishandles URL encoding. An attacker encodes part of the request path so that an authentication rule meant to guard one API endpoint no longer matches it, according to The Hacker News. The bypass covers a single endpoint, but that endpoint grants administrator privileges on the API.
No credentials, user interaction or special configuration are needed. The precondition is network reach to the Manager, so an instance with ports exposed to the internet is the case Cisco and Rapid7 both flag as at risk. Cisco's only mitigation text, as relayed by Rapid7, is to restrict access from unsecured networks and place systems behind filtering devices.
Cisco's Product Security Incident Response Team said it became aware of active exploitation in September 2026. The vulnerability was found during a Technical Assistance Center support case, which suggests a customer's compromised system surfaced it rather than a researcher's report.
Which release to move to
| Release train | First fixed release |
|---|---|
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Anything earlier than 20.9 must migrate to a fixed release, since no patch is listed for those trains. Cisco SD-WAN Cloud deployments that Cisco manages were patched in release 20.15.605 and need no action.
How to check whether you were hit
Cisco's advisory, as summarized by The Hacker News, tells administrators to look for j_security_check entries from unauthorized IP addresses in two logs: /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log. Any character in the path may be URI-encoded, so %6a can stand in for the letter j. A search for the literal string will miss encoded requests.
Rapid7 counts this as the third authentication bypass in the product's control components in 2026, after CVE-2026-20127 and CVE-2026-20182. The Hacker News lists three earlier SD-WAN fixes instead: CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June. The two outlets disagree on the list, and neither source names a threat actor or a victim count for this flaw.
The score does not overstate the risk for an exposed Manager, because the attacker ends up with administrative API control of the system that pushes configuration to the whole SD-WAN fabric. For an instance reachable only from a management network, the practical exposure is lower, but there is still nothing to apply except the update.
Patch to the release in the table, search both logs for encoded j_security_check requests, and take the Manager's interface off any network you do not control before the Oct. 3 federal deadline. For another CISA-listed authentication gap with no vendor patch, see our report on the Monta EV charging platform, and for a firmware fix on building controllers, the Johnson Controls EasyIO Neo story.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.
- 04Monta's EV Charging Platform Has No Patch for a 9.4 Authentication GapCISA lists four flaws in monta.app, all versions. The vendor points operators to an optional OCPP security profile and has shipped no fix.