Cisco Catalyst SD-WAN Manager CVE-2026-76504: Patch Now
CISA confirms active exploitation of a critical, unauthenticated Cisco Catalyst SD-WAN Manager auth-bypass flaw and gives federal agencies until October 3 to patch.

Cisco Catalyst SD-WAN Manager has a critical, actively exploited authentication-bypass flaw — CVE-2026-76504 — that lets an unauthenticated remote attacker reach the product's API with admin-level privileges, and CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026 with a federal patch deadline of October 3, 2026. Cisco rates the bug 9.8 out of 10 (Critical) and says its own Product Security Incident Response Team (PSIRT) has confirmed active exploitation in the wild.
Quick facts
- CVE: CVE-2026-76504 (CWE-177, improper handling of URL encoding)
- CVSS: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Affected product: Cisco Catalyst SD-WAN Manager (formerly vManage), on-prem deployments, regardless of configuration
- Fixed in: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 (Cloud-hosted 20.15.605 already remediated)
- Added to CISA KEV: September 30, 2026
- Federal patch deadline: October 3, 2026 (per CISA Binding Operational Directive 26-04)
- Workarounds: None — upgrade is the only fix
What happened
Cisco published security advisory cisco-sa-sdwan-webauth-xr8beuuU on September 30, 2026, disclosing the "Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability." The next day, CISA added the flaw to its Known Exploited Vulnerabilities catalog, a running list of security bugs the agency has evidence are being actively abused in real-world attacks. Government agencies and, by extension, the wider security community treat a KEV listing as a strong signal that a given vulnerability needs to be patched immediately rather than queued behind routine maintenance.
This marks the second Cisco Catalyst SD-WAN Manager advisory to land on security teams' desks in recent months — Pandromeda previously covered a separate set of actively exploited Cisco zero-days affecting the company's Identity Services Engine, a different product line. CVE-2026-76504 is unrelated to that incident but follows the same pattern: a widely deployed Cisco management platform, an authentication weakness, and confirmed in-the-wild abuse.
Why an SD-WAN Manager bug is such a high-value target
Catalyst SD-WAN Manager (the product most admins still know by its older name, vManage) is the single pane of glass that controls an entire Cisco SD-WAN fabric: it pushes configuration to every edge router and controller in the network, manages certificates, and holds admin credentials for the fleet underneath it. That centralization is exactly what makes it useful for network teams — and exactly what makes it dangerous in the hands of an attacker. Gaining admin-level API access to SD-WAN Manager doesn't just expose one device; it can expose the policy and routing configuration for every branch, data center, and cloud edge connected to that fabric. For large enterprises and service providers, that's effectively the keys to the whole wide-area network.
It's also why Cisco Catalyst SD-WAN infrastructure keeps showing up in KEV listings and advisory cycles — management-plane software that sits in front of an entire network is a persistently attractive target, and Cisco has published several Catalyst SD-WAN Manager advisories across 2026 alone, covering different CVEs and different root causes. CVE-2026-76504 is the latest, and per both Cisco and CISA, the first in that line this year with confirmed real-world exploitation behind it.
What the vulnerability actually is
According to Cisco's advisory, the flaw lives in the API session-based authentication management of Catalyst SD-WAN Manager, the centralized controller administrators use to configure and monitor an SD-WAN fabric. The root cause is improper handling of URI encoding in HTTP requests: by hex-encoding a single character in the request path, an attacker can get a request to slip past an authentication rule that is supposed to restrict access to a specific API endpoint.
Cisco's own indicator-of-compromise examples show attackers substituting %6a — the hex-encoded form of the letter "j" — into the login-handling path, turning a request into something like /%6a_security_check. Because the encoded character still resolves to the same literal path once decoded, the server processes it as a legitimate authentication-flow request while the access-control check that should have blocked it never fires. The practical result, in Cisco's words, is that "an attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system" and, if successful, "bypass authentication and gain access to the API as the admin user" — no credentials, no user interaction, no prior access required. That combination is why the CVSS score lands at the maximum severity band.
Cisco credits the discovery to its own Technical Assistance Center (TAC), saying the issue "was found during the resolution of a Cisco TAC support case" — meaning this started as a real customer incident rather than an outside researcher's lab finding, which lines up with CISA's decision to fast-track it onto the KEV list.
Affected products and versions
Cisco says the vulnerability affects Catalyst SD-WAN Manager "regardless of system configuration," meaning there is no setting that disables the vulnerable code path. The advisory lists vulnerable releases across six train lines, with the first fixed build for each:
| Affected release train | Status | First fixed release |
|---|---|---|
| Earlier than 20.9 | Vulnerable | Migrate to a fixed release |
| 20.9 | Vulnerable | 20.9.10.1 |
| 20.12 | Vulnerable | 20.12.8.2 |
| 20.15 | Vulnerable | 20.15.6.1 |
| 20.18 | Vulnerable | 20.18.4.1 |
| 26.1 | Vulnerable | 26.1.2.1 |
| 26.2 | Vulnerable | 26.2.1 |
| SD-WAN Cloud (Cisco Managed), Release 20.15.605 | Remediated by Cisco | No customer action required |
If you run Catalyst SD-WAN Manager on-premises or as self-managed cloud infrastructure, you need to upgrade yourself — there is no automatic patching. Cisco's cloud-hosted ("Cisco Managed") offering on Release 20.15.605 has already been remediated on Cisco's side, and the company says customers on that specific managed release do not need to take action, though it's worth confirming your exact deployment type and release rather than assuming you're covered. Cisco notes that customers can check their current remediation status or software version using the Help function inside the service GUI.
Why CISA added it to the KEV catalog
CISA's Known Exploited Vulnerabilities catalog only includes bugs the agency has evidence are being exploited in active attacks — it is not a general severity list. CISA's entry for this bug, titled "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability," was added on September 30, 2026, directly citing Cisco's advisory and the matching NVD record for CVE-2026-76504. Cisco's own advisory corroborates this, stating plainly that "in September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability" and urging customers to upgrade immediately rather than rely on mitigations.
Notably, CISA flagged this entry for mandatory forensic triage — a stricter category of required action the agency reserves for KEV entries where there's elevated concern about post-exploitation compromise, not just patching. That's on top of the standard remediation requirement, and it signals CISA views this less as "patch when convenient" and more as "assume compromise may already have occurred and go check."
The federal patch deadline — and why it's unusually tight
Once a vulnerability lands in the KEV catalog, U.S. federal civilian executive branch agencies are required to remediate it by a specific date under CISA's Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk", the current framework governing how quickly agencies must act on KEV-listed flaws. For CVE-2026-76504, CISA set a due date of October 3, 2026 — just three days after the vulnerability was added to the catalog. That's a notably compressed window; many KEV entries carry deadlines of two to three weeks, but CISA can and does shorten the timeline for vulnerabilities it considers especially severe or where exploitation evidence is strong, which the critical 9.8 CVSS score and confirmed active exploitation here both support.
BOD deadlines are legally binding only on federal civilian agencies, but security teams across every sector treat them as the de facto industry clock: if CISA is telling the government to patch in three days, that's a strong signal for any organization running exposed Catalyst SD-WAN Manager instances to move with the same urgency, not wait for a routine patch cycle.
Indicators of compromise to check now
Because this bug has already been exploited, patching alone may not be enough if an attacker got in before you upgraded. Cisco's advisory includes specific log-based indicators of compromise (IOCs) administrators should check immediately:
- Audit
serviceproxy-access.log(located at/var/log/nms/containers/service-proxy/serviceproxy-access.log) forj_security_checkrequests containing hex-encoded characters — Cisco's example uses%6ain place of the letter "j" — originating from unknown or unauthorized IP addresses. - Audit
vmanage-server.log(located at/var/log/nms/vmanage-server.log) forj_security_checkentries tied to accounts whose usernames begin withviptela-reserved-, a naming pattern associated with internal service accounts that shouldn't normally show up authenticating this way from external sources.
Cisco cautions that some matching log entries can occur during normal operations, so any hits need to be assessed against your organization's typical traffic patterns before concluding you've been compromised. If you find suspicious entries, Cisco recommends opening a Severity 3 case with the Cisco Technical Assistance Center (TAC), citing CVE-2026-76504 in the case title, and running the request admin-tech command on the affected Catalyst SD-WAN Manager instance beforehand so TAC has the diagnostic bundle it needs to help determine whether the system was actually compromised.
No workarounds — only mitigations
Cisco is explicit that there are no workarounds that fully address this vulnerability. The only real fix is upgrading to one of the patched releases listed above. In the meantime, Cisco's interim mitigation advice — consistent with its standing Catalyst SD-WAN hardening guidance — is to prevent any internet-facing access to SD-WAN Manager wherever possible, and where remote access is unavoidable, to restrict it to known, trusted hosts over a firewall or similar filtering device rather than leaving the management interface broadly reachable. Cisco notes that for its own Cloud Hosted environments this network-level mitigation is already deployed by default, but on-premises customers are responsible for implementing it themselves.
What admins should do now
If you operate Cisco Catalyst SD-WAN Manager, treat this as a same-week priority, not a routine patch-cycle item:
- Identify every Catalyst SD-WAN Manager instance in your environment and confirm its exact release version against Cisco's affected-versions table above.
- Upgrade immediately to the first fixed release for your train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1), or migrate off any release earlier than 20.9 entirely, since Cisco offers no fix for those builds.
- Check the IOC logs described above —
serviceproxy-access.logandvmanage-server.log— for signs the system may already have been accessed before you patched. - Restrict management-plane exposure so SD-WAN Manager isn't reachable from the open internet, and limit access to known, trusted hosts through a firewall in the interim.
- Open a TAC case if you find anything suspicious in the logs, rather than assuming a clean patch resolves a prior compromise.
Security and IT teams juggling this alongside everything else on their plate this week — including rollouts like ChatGPT's newly default-enabled integration into Microsoft Word, Excel, and PowerPoint — should still put this Cisco patch ahead of routine software updates, given CISA's confirmation of active exploitation and the unusually short federal remediation window. It's a similar calculus to the one Pandromeda outlined when MikroTik routers landed on the KEV catalog under active attack and when a critical WordPress RCE flaw got the same "patch now" treatment: internet-facing management infrastructure with a confirmed-exploited authentication bypass doesn't get the luxury of a maintenance window.
What's next
Expect Cisco to continue monitoring for further exploitation activity and to update its advisory if new fixed releases or additional indicators of compromise emerge — the advisory is currently Version 1.0, so revisions are possible. Federal civilian agencies are on the clock to remediate by October 3, 2026 under BOD 26-04, and any organization running an internet-reachable Catalyst SD-WAN Manager instance that hasn't yet upgraded should assume it's a live target: this is not a theoretical bug sitting in a research paper, it's one CISA and Cisco have both confirmed is being actively used against real deployments.
Frequently asked questions
What is CVE-2026-76504?
CVE-2026-76504 is a critical authentication-bypass vulnerability in Cisco Catalyst SD-WAN Manager. It stems from improper handling of URI encoding in HTTP requests, which lets an unauthenticated remote attacker send a crafted request that bypasses an authentication rule and gain access to the product's API with admin-user privileges. Cisco rates it 9.8 (Critical) on the CVSS 3.1 scale.
Is Cisco Catalyst SD-WAN Manager actually being attacked right now?
Yes. Cisco's own Product Security Incident Response Team (PSIRT) says it became aware of active exploitation of this vulnerability in September 2026, and the bug was found while resolving a real Cisco TAC customer support case. CISA added it to its Known Exploited Vulnerabilities catalog on September 30, 2026 on that basis.
Which Catalyst SD-WAN Manager versions are affected, and what should I upgrade to?
Any release earlier than 20.9 is vulnerable with no fix (migrate to a supported release). Vulnerable builds in the 20.9, 20.12, 20.15, 20.18, 26.1, and 26.2 trains should be upgraded to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1 respectively. Cisco's own SD-WAN Cloud (Managed) Release 20.15.605 has already been remediated and needs no customer action.
What is CISA's deadline for patching this vulnerability?
CISA set a due date of October 3, 2026 for U.S. federal civilian agencies under Binding Operational Directive 26-04, just three days after the CVE was added to the KEV catalog on September 30, 2026 — a notably short window compared to the two-to-three weeks many KEV entries allow.
Are there workarounds if I can't patch Catalyst SD-WAN Manager immediately?
Cisco says there are no workarounds that fully address the vulnerability. The interim mitigation is to eliminate internet-facing access to SD-WAN Manager and restrict any required remote access to known, trusted hosts behind a firewall, per Cisco's hardening guidance. Cisco's own Cloud Hosted environments already have this mitigation deployed by default.
How do I check if my SD-WAN Manager has already been compromised?
Cisco recommends auditing serviceproxy-access.log for j_security_check requests containing hex-encoded characters (such as %6a) from unauthorized IPs, and vmanage-server.log for j_security_check activity tied to accounts starting with viptela-reserved- from unexpected sources. If you find suspicious entries, open a Severity 3 TAC case citing CVE-2026-76504.
Sources
- Cisco Security Advisory: Catalyst SD-WAN Manager API Authentication Bypass Vulnerability (cisco-sa-sdwan-webauth-xr8beuuU)sec.cloudapps.cisco.com
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
- NVD: CVE-2026-76504 Detailnvd.nist.gov
- CISA Binding Operational Directive 26-04: Prioritizing Security Updates Based on Riskcisa.gov
- Cisco Catalyst SD-WAN Solutionscisco.com
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


