Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco in an advisory on September 30.
See also: Cisco: Two vulnerabilities in Catalyst SD-WAN Manager actively exploited

The flaw, CVE-2026-76504, could allow a remote attacker without login access to use the Manager API as an administrator. Patches are available and there is no workaround.
CVE-2026-76504 has a CVSS score of 9.8 out of 10.It is located in the part of the Manager API that handles login sessions. The Manager incorrectly handles URI encoding in an HTTP request, allowing a crafted request to bypass an authentication rule intended to limit access to a single API endpoint.
The attacker doesn't need credentials, just the ability to send this request to the Manager's API. Managers exposed to the internet are at risk of being compromised, according to Cisco. By default, the manager holds the netadmin role, which is allowed to perform all operations on the device.
Cisco said its Product Security Incident Response Team “was made aware of active exploitation of this vulnerability” in September 2026. The flaw was discovered while Cisco’s Technical Assistance Center (TAC) was handling a support case. The advisory does not specify how many customers were attacked, when the attacks began, who carried them out, or what the attackers did with the access.
The bug affects SD-WAN Manager regardless of how the system is configured. No other products are listed as affected. These are the first fixed releases for each release line:
CVE-2026-76504 is separate from three Cisco SD-WAN vulnerabilities that were previously patched: CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June. A comparison of the advisories shows that the patch versions for these vulnerabilities are all older than those in the table above. Thus, a Manager that was last upgraded for the May or June patches still needs this update.
See also: CVE-2026-76461: Critical zero-day in Cisco Secure Email Gateway

Cisco SD-WAN Cloud (Cisco Managed) has already been patched in version 20.15.605, and customers on it do not need to take any action. Until an on-prem Manager is upgraded, Cisco advises restricting access to it from unsecured networks such as the internet. Where internet access is required, only known, trusted hosts should be allowed, and controls should be behind a firewall.
Environments hosted on Cisco Catalyst SD-WAN Cloud already have this mitigation in place. The mitigation worked in a test environment, according to Cisco, which advises customers to evaluate its impact on their own networks before implementing it.
The Cisco SD-WAN hardening guide states that management interfaces, such as ports 443, 22, and 830, should not be exposed directly to the internet. HTTPS access to the Manager should only be from an intermediate host or management subnet.
The signs of compromise described by Cisco include j_security_check, the request path used by Manager for session-based connections. In Cisco's example, one character in this path is URI-encoded, resulting in /%6a_security_check, where %6a represents the letter j.
Two log files are the places to look for j_security_check entries from unknown or unauthorized IP addresses:
- /var/log/nms/containers/service-proxy/serviceproxy-access.log
- /var/log/nms/vmanage-server.log, especially entries for users whose names start with viptela-reserved-
Names starting with viptela-reserved- belong to system service accounts that are reserved. Any character in the request can be encoded, so %6a is just an example. The same entries can also appear during normal operation, and each match should be checked against normal activity to avoid false positives.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Cisco ISE: Critical vulnerability under active exploitation

To help determine if a Manager has been compromised, customers can open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the subject line. Cisco asks that they run the admin-tech request on the Manager first so that the output file can be reviewed. The advisory does not include a detection rule and does not specify whether the upgrade removes an attacker who already has access.
