HomeSecurityCisco Catalyst SD-WAN Manager: Critical vulnerability in the KEV Catalog

Cisco Catalyst SD-WAN Manager: Critical Vulnerability in KEV Catalog

The cybersecurity community has been alarmed after a critical vulnerability in Cisco Catalyst SD-WAN Manager was added to the CISA Known Exploited Vulnerabilities (KEV) list . The move comes after reports that the vulnerability is already being exploited in real-world attacks , raising the need for immediate testing and implementation of available fixes.

Article Image: CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The vulnerability is listed as CVE-2026-76504 and has a CVSS score of 9.8/10, making it one of the most severe security vulnerabilities. The issue concerns the authentication mechanism of the SD-WAN Manager and could allow a remote attacker without valid credentials to gain administrative access.

The development is particularly important for enterprises that use SD-WAN to centrally manage distributed networks, as a breach of such a platform can create broader risks to the network infrastructure.

How the vulnerability in Cisco Catalyst SD-WAN Manager works

According to CISA, CVE-2026-76504 is related to incorrect handling of URI encoding in HTTP requests. Specifically, the issue concerns the way Cisco Catalyst SD-WAN Manager processes certain data encoded in hexadecimal format.

An unauthenticated remote attacker could exploit the vulnerability by sending a specially crafted HTTP request to the platform's API. If the attack is successful, the authentication mechanism could be bypassed, allowing access to the API with administrator privileges.

See also: Cisco warns of attacks exploiting vulnerability in SD-WAN Manager

What significantly increases the seriousness of the case is that no prior authentication is required. In other words, the attacker does not need to already have an account on the platform to attempt the exploit.

Cisco confirmed active exploitation

Cisco announced in September 2026 that it had been made aware of active exploitation of this vulnerability. The company has made Indicators of Compromise (IoCs) available, allowing administrators to look for signs of suspicious activity in their environments.

Among the checks suggested is examining the /var/log/nms/containers/service-proxy/serviceproxy-access.log file for j_security_check -related entries originating from unknown or unauthorized IP addresses.

At the same time, administrators should check /var/log/nms/vmanage-server.log, looking for corresponding entries and specifically requests related to accounts whose names start with the prefix viptela-reserved-.

bypassing identity verification - SecNews.gr

Why SD-WAN Manager is an attractive target

The incident takes on even greater significance due to the role that SD-WAN Manager plays in an enterprise network. It is a centralized platform through which administrators can monitor, configure, and control different network segments from a single environment.

See also: CVE-2026-20262: Cisco SD-WAN Manager actively exploited

This means that a breach of the central management system can give an attacker a particularly wide field of action. Instead of targeting individual devices, they can attempt to leverage the platform's central position to gain further access to the infrastructure.

Jake Knott, head of threat intelligence at watchTowr, noted that the number of Cisco SD-WAN vulnerabilities added to the KEV list in 2026 demonstrates the attackers' interest in the platform. This observation is an assessment by the company and not an official finding by CISA.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What should organizations do?

CISA has listed CVE-2026-76504 as KEV, which means the vulnerability is being treated as an issue that has already been exploited in attacks. U.S. federal agencies have until October 3, 2026 , to implement the required fixes.

For other organizations, the priority is to upgrade Cisco Catalyst SD-WAN Manager to the version that includes the fix. In the meantime, security teams should look for suspicious POST requests to variations of the /j_security_check, especially when URL encoding is used.

CVE-2026-20262 Cisco Catalyst SD-WAN Manager vulnerability active exploitation

However, patching should not be considered the only step. In environments where there are indications of exploitation, it is necessary to review logs, investigate possible accounts created without authorization, and look for unusual activity after initial access.

See also: Cisco Catalyst SD-WAN Controller: Critical zero-day vulnerability fixed

Cisco has not yet released details on the number of organizations that may have been affected, the identity of the perpetrators, or the exact timing of the exploit, making it all the more important to proactively monitor installations using the platform.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS