Thehackernews iconThehackernewsSep 30, 2026 ~7 min source read

Cisco: Critical SD‑WAN Manager Authentication Bypass (CVE‑2026‑76504) Is Being Exploited

A remote attacker can bypass authentication on Cisco Catalyst SD‑WAN Manager’s API and act as admin without credentials. Fixed releases are available; there is no workaround.

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Share this story

Send the public story page.

Useful takeaways from this story.

The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user.

How to Find, Authorize and Govern Every AI Agent in Your Environment AI agents are already operating inside enterprises with growing access to sensitive systems and data—while security teams still lack the...

It sits in the part of the Manager's API that handles login sessions.

# What happened Cisco reported active exploitation of a critical zero‑day in Catalyst SD‑WAN Manager (CVE‑2026‑76504) on September 30, 2026. The vulnerability is an authentication bypass in the Manager's API that allows a remote attacker to issue requests as the admin user without supplying credentials. Cisco's Product Security Incident Response Team learned of attacks while its TAC was handling a support case.

# How the flaw works The Manager mishandles URI encoding in HTTP request paths used for session login. A crafted request that encodes a single character in the login path (for example, replacing j_security_check with /%6a_security_check) can bypass an authentication restriction that was intended to limit access to a single endpoint. The attacker only needs the ability to send that request to the Manager's API. By default the admin account holds the netadmin role, which can perform all operations on the device.

# Who is affected All on‑premises Cisco Catalyst SD‑WAN Manager deployments are affected regardless of configuration. Cisco SD‑WAN Cloud (Cisco Managed) is already fixed in release 20.15.605 and requires no customer action. The advisory does not list SD‑WAN Cloud‑Pro or FedRAMP variants for this specific bulletin.

# Fixed releases (first fixed per train)

  • Earlier than 20.9: migrate to a fixed release
  • 20.9: 20.9.10.1
  • 20.12: 20.12.8.2
  • 20.15: 20.15.6.1
  • 20.18: 20.18.4.1
  • 26.1: 26.1.2.1
  • 26.2: 26.2.1

Note: release trains such as 20.10, 20.11, 20.13, 20.14, and 20.16 are not listed in this advisory. Managers updated for earlier 2026 SD‑WAN fixes (May/June) still need this update.

# Immediate mitigations to apply

  • Do not expose administrative interfaces (ports 443, 22, 830) directly to the internet.
  • Place control components behind a firewall or management jump host or on a management subnet for HTTPS access.

# How to check for compromise

  • Look for requests to the login path or its URI‑encoded variants (j_security_check, /%6a_security_check, or any other single‑character encoded variant).
  • These entries can appear in normal traffic. Compare matches to normal activity to avoid false positives.
  • If compromise is suspected, open a Severity 3 case with Cisco TAC and include CVE‑2026‑76504 in the title. Run request admin-tech on the Manager first and provide the output for TAC review.

# Important operational notes

  • Cisco's advisory provides no workaround and no detection signatures. Fixed releases exist, but the advisory does not explicitly state whether upgrading ejects an attacker who already has access. Earlier Cisco advisories for other 2026 SD‑WAN flaws warned that updates alone might not resolve a confirmed compromise and instructed customers to collect admin‑tech output before upgrading.

# Action checklist for operators

  • Block or restrict external access immediately and allow only trusted hosts or a jump host to reach the Manager.
  • Plan and deploy the appropriate fixed release for your train as soon as possible.
  • Search logs for URI‑encoded login path requests and gather admin‑tech output if suspicious activity appears. Open a Severity 3 TAC case with Cisco if you suspect compromise.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app