Cyber One Solutions logo.
Get Support

Security Advisory

CVE-2026-76504: Cisco Confirms Active Exploitation of a Critical SD-WAN Manager Authentication Bypass

October 6, 2026 · Cyber One Solutions Security Team

Cisco disclosed a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager that lets an unauthenticated attacker reach the management API with admin privileges, and confirmed its own security team found it being actively exploited. CISA added it to the Known Exploited Vulnerabilities catalog the same day, with an October 3 federal deadline and no vendor workaround.

Cisco published security advisory cisco-sa-sdwan-webauth-xr8beuuU on September 30, 2026, disclosing CVE-2026-76504, an authentication bypass in Catalyst SD-WAN Manager with a CVSS v3.1 base score of 9.8. Cisco's advisory states plainly that "in September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability." CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog that same day, listing it as the "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability" and setting an October 3, 2026 remediation due date for federal civilian agencies under Binding Operational Directive 26-04, according to Cisco's security advisory and CISA's Known Exploited Vulnerabilities catalog.

What SD-WAN Manager Controls, and Why a Bypass Here Matters

Catalyst SD-WAN Manager is the centralized console that configures and monitors a Cisco SD-WAN fabric: the routing policy, security policy, and traffic-prioritization rules that decide how a multi-site business moves voice, video, and cloud application traffic across its internet circuits between locations. It is the single console an IT team or managed provider logs into to manage that fabric network-wide rather than device by device. Cisco's advisory is specific that this flaw sits in SD-WAN Manager itself and does not affect the cEdge or vEdge router hardware, or the vBond and vSmart controllers, that make up the rest of the fabric. That distinction matters for scoping your exposure: an organization running SD-WAN edge routers without a Catalyst SD-WAN Manager console, for example one managed entirely by a provider's own separate management plane, is not described as affected by this specific advisory. An organization that does run its own SD-WAN Manager console, however, is looking at an unauthenticated path to the one piece of software with administrative reach over its entire WAN policy.

What the Vulnerability Is, and How It Works

Cisco attributes the flaw to improper handling of URI encoding in SD-WAN Manager's API session-based authentication, tracked under CWE-177. The advisory's own indicator-of-compromise guidance illustrates the mechanism directly: it shows requests using "%6a" as the URI-encoded form of the letter "j" sent against the system's j_security_check authentication endpoint, where inconsistent handling of that encoding lets the request slip past the authentication rule meant to protect it. Cisco notes other encoded characters beyond %6a could potentially be used the same way. The CVSS vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, means the flaw is reachable over the network, takes low attack complexity, and needs no privileges or user interaction at all; a successful exploit hands the attacker admin-level access to the management API. Cisco's advisory does not say exactly when in September its PSIRT first observed exploitation, only that it became aware of it that month, so an exposed instance should not be assumed safe just because today's date is after the disclosure.

Affected and Fixed Versions

Cisco's advisory lists Catalyst SD-WAN Manager releases earlier than 20.9 as vulnerable with no direct fix, meaning those need to be upgraded to a supported branch before this patch even applies. Within supported branches, the advisory lists 20.9 before 20.9.10.1, 20.12 before 20.12.8.2, 20.15 before 20.15.6.1, 20.18 before 20.18.4.1, 26.1 before 26.1.2.1, and 26.2 before 26.2.1 as vulnerable. Cisco also fixed the flaw in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605 and states that customers on that Cisco-managed service need take no action. That release applies only to the Cisco-managed service: an SD-WAN Manager instance your organization or provider runs itself, including one hosted in AWS, Azure, or another cloud, needs the fixed release for its own branch from the list above. Confirm your deployment's exact version against these thresholds rather than assuming a recent update already covers it.

What to Do Now

Confirm whether your organization, or whichever managed provider operates your SD-WAN fabric, runs a Catalyst SD-WAN Manager console, and at what version; the cEdge, vEdge, vBond, and vSmart components of the same fabric are not what this advisory is about. Apply the fixed release for your branch on an emergency basis. Cisco states there are no workarounds that address this vulnerability, so upgrading is the only remediation. Two measures can reduce exposure while an upgrade is scheduled. For on-premises deployments, the advisory recommends blocking access from the internet and other untrusted networks, allowing only known, trusted hosts through a firewall; Cisco states this mitigation is already in place for its Cloud Hosted environments. On October 2, Cisco also updated the advisory to add a Live Protect shield for this CVE, which it describes as offering only temporary, partial protection to allow time for upgrade planning, with one documented side effect: once the shield is applied, a legitimate user whose login uses URI encoding might not be able to sign in to SD-WAN Manager. Treat both as stopgaps, not substitutes for the upgrade. If your SD-WAN Manager console has been reachable from the public internet at any point before you applied the fixed release, treat that as a possible compromise rather than only a missing patch. Cisco says internet-exposed systems are at risk, and it has not said exploitation stopped after September. Before you assume the update alone resolved the risk, run both of the checks Cisco documents: search serviceproxy-access.log for j_security_check requests from unknown or unauthorized IP addresses, and search vmanage-server.log for j_security_check calls made for usernames beginning with viptela-reserved-, an indicator that will not show up in an IP-based search alone. Then review administrative-session activity for anything you cannot account for.

What This Means for Your Risk-Management Obligations

For businesses subject to the FTC Safeguards Rule or the HIPAA Security Rule, the same obligations that applied to the Cisco and Citrix advisories we have covered recently apply here. The FTC Safeguards Rule requires nonbanking financial institutions to maintain a documented information security program that includes vulnerability monitoring under 16 CFR 314.4(d)(2), though institutions maintaining customer information on fewer than 5,000 consumers are exempt from that rule's specific written risk-assessment and periodic vulnerability-testing requirement. HHS Office for Civil Rights guidance is explicit that identifying and remediating known, actively exploited vulnerabilities in network infrastructure falls within the ongoing risk analysis and risk management obligations at 45 CFR 164.308(a)(1)(ii)(A) and (B), and an administrative console with policy control over the WAN carrying that traffic is squarely the kind of infrastructure that guidance covers.

If your organization runs Catalyst SD-WAN Manager, confirm your version and patch status today. Cyber One Solutions designs, manages, and monitors SD-WAN deployments as part of our managed internet and SD-WAN service, and our managed cybersecurity service's vulnerability management program continuously scans for findings like this one, prioritizes them using data such as the CISA KEV catalog, and tracks remediation through to a validated fix. If you are evaluating a network or SD-WAN provider and want to know what to ask them about situations exactly like this one, our networking buyer's guide covers the questions worth asking before you sign. Our IT and security assessments can also confirm your current exposure across your network infrastructure as a standalone engagement.

Sources