Skip to main content
QUIETLYTIC
Active exploitation

Exploited Cisco SD-WAN Manager flaw gives attackers admin API access

CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass to its KEV catalog with a three-day federal deadline and a required compromise check.

Category
Active exploitation
Severity
Critical
CVEs
CVE-2026-76504

Attackers are abusing an authentication bypass in Cisco Catalyst SD-WAN Manager, the controller that pushes configuration and policy to the routers across an organisation’s SD-WAN. The US Cybersecurity and Infrastructure Security Agency added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog on 30 September, the same day the CVE was published, and gave federal civilian agencies until 3 October to act. An unauthenticated request from the network can reach the product’s API with administrator rights, so an exposed manager is a direct route to reconfiguring an entire SD-WAN fabric.

A request-parsing mistake with full admin consequences

The weakness is classed as CWE-177, improper handling of URL encoding. SD-WAN Manager applies an authentication rule to a particular API endpoint, but it does not normalise percent-encoded characters in the request path before checking that rule. A path written in encoded form slips past the check while still being routed to the protected endpoint, and the caller ends up holding an API session with the privileges of the admin user.

Cisco scores the issue 9.8 under CVSS 3.1, the Critical band: network reachable, low complexity, no credentials and no user interaction. CISA’s own SSVC assessment in the CVE record is just as blunt. It lists exploitation as active, the attack as automatable and the technical impact as total. That last combination, automatable with total impact, is the one that lets an attacker sweep the internet for exposed managers rather than work target by target.

Cisco says the flaw is present in every SD-WAN Manager deployment regardless of configuration, and that no configuration workaround closes it.

What the government record confirms

  • Active exploitation. CISA added the entry on the basis of evidence of exploitation in the wild. Cisco, which assigned the CVE, separately says its product security team learned of attacks during September and that the flaw was found while a support case was being resolved.
  • A three-day clock. The KEV due date is 3 October. Under Binding Operational Directive 26-04, a KEV entry gets a three-day deadline when the flaw sits on a publicly exposed asset, gives total control of it, and can be automated by an attacker. CISA’s assessment of this one ticks all three.
  • A compromise check, not only a patch. The catalog marks the entry for forensic triage. Federal agencies must preserve evidence from each manager before they upgrade it, then analyse that evidence for signs of compromise, rather than simply installing the fix and moving on.
  • Ransomware use unknown. CISA records the ransomware connection as unknown; it has not established a link either way.

What remains undisclosed matters as much. Neither CISA nor Cisco has said who is exploiting the flaw, how many organisations have been hit, which sectors or regions are affected, or what attackers did once they held admin access. No threat group has been named. Claims elsewhere of specific campaigns should be treated as unconfirmed until a government source makes them.

Which releases are fixed

Every supported release train has a fix. Working from newest to oldest, Cisco names these as the first fixed builds:

  • 26.2 train: upgrade to 26.2.1 or later.
  • 26.1 train: upgrade to 26.1.2.1 or later.
  • 20.18 train: upgrade to 20.18.4.1 or later.
  • 20.15 train: upgrade to 20.15.6.1 or later.
  • 20.12 train: upgrade to 20.12.8.2 or later.
  • 20.9 train: upgrade to 20.9.10.1 or later.

Anything older than 20.9 has no fix and needs to migrate to a supported train. The Cisco-managed cloud service was updated by the vendor and needs no customer action, and Cisco says the network-access restriction described below is already in place for cloud-hosted tenants. On-premises deployments are the ones that need attention.

Priorities for SD-WAN operators

  1. Find every manager and check its exposure. List all SD-WAN Manager instances, including lab and disaster-recovery copies, and confirm whether their web interface or API answers from the internet. Exposed instances go first.
  2. Cut internet access now if you cannot upgrade today. Place the manager and the other control components behind a firewall that admits only known management hosts. Cisco describes this as mitigation, not a fix: it narrows who can reach the vulnerable endpoint but leaves the flaw in place.
  3. Capture evidence before upgrading. Generate the platform’s admin-tech diagnostic bundle and copy application logs off the appliance before changing anything. An upgrade can overwrite the traces a compromise check depends on.
  4. Look for unexpected authentication activity. Cisco points administrators to the service-proxy access log and the vManage server log. Review requests to the login endpoint from addresses you do not recognise, particularly any that resolve to the reserved internal system service accounts, which ordinary operators should never be signing in as. Cisco warns that some matching entries can occur in normal operation, so judge them against known management traffic. Cisco’s support centre will assist with triage for cases opened under the CVE number.
  5. Upgrade to the fixed release for your train. Check the compatibility of the other control components before scheduling the change.
  6. Treat a positive finding as a fabric-wide incident. An attacker with admin API access could have changed routing, security policy or device templates across every site the manager controls. Review recent configuration changes, audit user accounts, and rotate credentials and keys held by the manager.

Organisations outside the federal government are not bound by the 3 October date. The reasoning behind it still applies: this is a critical, automatable, already-exploited bypass in the system that controls the rest of the network. Related exploited network-infrastructure flaws are indexed in the CVE search.

Source: Cybersecurity and Infrastructure Security Agency (CISA)

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources

  1. CISA — CISA Adds One Known Exploited Vulnerability to Catalog (30 September 2026)
  2. CISA — Known Exploited Vulnerabilities Catalog
  3. CISA — BOD 26-04 Implementation Guidance: Prioritizing Security Updates Based on Risk
  4. NVD — CVE-2026-76504
  5. CVE.org — CVE-2026-76504
  6. Cisco PSIRT — Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability

Related intelligence


Analyst tools