The cybersecurity community has been alarmed after a critical vulnerability in Cisco Catalyst SD-WAN Manager was added to the CISA Known Exploited Vulnerabilities (KEV) list . The move comes after reports that the vulnerability is already being exploited in real-world attacks , raising the need for immediate testing and implementation of available fixes.

The vulnerability is listed as CVE-2026-76504 and has a CVSS score of 9.8/10, making it one of the most severe security vulnerabilities. The issue concerns the authentication mechanism of the SD-WAN Manager and could allow a remote attacker without valid credentials to gain administrative access.
The development is particularly important for enterprises that use SD-WAN to centrally manage distributed networks, as a breach of such a platform can create broader risks to the network infrastructure.
How the vulnerability in Cisco Catalyst SD-WAN Manager works
According to CISA, CVE-2026-76504 is related to incorrect handling of URI encoding in HTTP requests. Specifically, the issue concerns the way Cisco Catalyst SD-WAN Manager processes certain data encoded in hexadecimal format.
An unauthenticated remote attacker could exploit the vulnerability by sending a specially crafted HTTP request to the platform's API. If the attack is successful, the authentication mechanism could be bypassed, allowing access to the API with administrator privileges.
See also: Cisco warns of attacks exploiting vulnerability in SD-WAN Manager
What significantly increases the seriousness of the case is that no prior authentication is required. In other words, the attacker does not need to already have an account on the platform to attempt the exploit.
Cisco confirmed active exploitation
Cisco announced in September 2026 that it had been made aware of active exploitation of this vulnerability. The company has made Indicators of Compromise (IoCs) available, allowing administrators to look for signs of suspicious activity in their environments.
Among the checks suggested is examining the /var/log/nms/containers/service-proxy/serviceproxy-access.log file for j_security_check -related entries originating from unknown or unauthorized IP addresses.
At the same time, administrators should check /var/log/nms/vmanage-server.log, looking for corresponding entries and specifically requests related to accounts whose names start with the prefix viptela-reserved-.

Why SD-WAN Manager is an attractive target
The incident takes on even greater significance due to the role that SD-WAN Manager plays in an enterprise network. It is a centralized platform through which administrators can monitor, configure, and control different network segments from a single environment.
See also: CVE-2026-20262: Cisco SD-WAN Manager actively exploited
This means that a breach of the central management system can give an attacker a particularly wide field of action. Instead of targeting individual devices, they can attempt to leverage the platform's central position to gain further access to the infrastructure.
Jake Knott, head of threat intelligence at watchTowr, noted that the number of Cisco SD-WAN vulnerabilities added to the KEV list in 2026 demonstrates the attackers' interest in the platform. This observation is an assessment by the company and not an official finding by CISA.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What should organizations do?
CISA has listed CVE-2026-76504 as KEV, which means the vulnerability is being treated as an issue that has already been exploited in attacks. U.S. federal agencies have until October 3, 2026 , to implement the required fixes.
For other organizations, the priority is to upgrade Cisco Catalyst SD-WAN Manager to the version that includes the fix. In the meantime, security teams should look for suspicious POST requests to variations of the /j_security_check, especially when URL encoding is used.

However, patching should not be considered the only step. In environments where there are indications of exploitation, it is necessary to review logs, investigate possible accounts created without authorization, and look for unusual activity after initial access.
See also: Cisco Catalyst SD-WAN Controller: Critical zero-day vulnerability fixed
Cisco has not yet released details on the number of organizations that may have been affected, the identity of the perpetrators, or the exact timing of the exploit, making it all the more important to proactively monitor installations using the platform.
