A critical vulnerability (CVSS 9.8) has been identified in Cisco Catalyst SD-WAN Manager and is confirmed to be actively exploited in the wild. An unauthenticated remote attacker can gain administrative privileges and fully control the SD-WAN infrastructure via the management API. Given the central role of SD-WAN managers, this represents a severe risk to the entire WAN infrastructure.
-
Affected Systems and Versions Affected Product: Cisco Catalyst SD-WAN Manager (formerly vManage)
The vulnerability stems from improper handling of the login endpoint (j_security_check), where specially crafted or encoded requests can bypass authentication.
Vulnerable Versions:
-
Prior to 20.9: All versions
-
20.9.x: Versions prior to 20.9.10.1
-
20.12.x: Versions prior to 20.12.8.2
-
20.15.x: Versions prior to 20.15.6.1
-
20.18.x: Versions prior to 20.18.4.1
-
26.1.x: Versions prior to 26.1.2.1
-
26.2.x: Versions prior to 26.2.1
-
Action Items and Recommendations
Priority 1: Apply Security Updates Immediately Cisco strongly recommends upgrading immediately to the following safe releases:
-
Release Train 20.9 -> Fixed in 20.9.10.1
-
Release Train 20.12 -> Fixed in 20.12.8.2
-
Release Train 20.15 -> Fixed in 20.15.6.1
-
Release Train 20.18 -> Fixed in 20.18.4.1
-
Release Train 26.1 -> Fixed in 26.1.2.1
-
Release Train 26.2 -> Fixed in 26.2.1
-
Cisco SD-WAN Cloud -> 20.15.605
Priority 2: Check for Indicators of Compromise (IoC) Cisco suggests inspecting the following log files for signs of exploitation:
-
/var/log/nms/serviceproxy-access.log
-
/var/log/nms/vmanage-server.log
Search for: /%6a_security_check
The presence of this string alone does not confirm a successful breach, but it indicates potential attack attempts and should be thoroughly investigated.
Priority 3: Restrict Management Access Until patches can be applied:
-
Block all public internet access to the SD-WAN Manager.
-
Restrict access strictly to trusted administrative networks or VPNs.
-
Enforce management port restrictions via firewalls.
-
Minimize external exposure.
These steps follow standard Cisco and incident response best practices for actively exploited management plane vulnerabilities.
Official Cisco References
-
Cisco Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass
-
Cisco SD-WAN Security Advisories Overview: Cisco SD-WAN - Security Advisories, Responses and Notices
-
Cisco Software Downloads: Cisco Software Central (Login required)
3. Related CVEs (Sorted by Severity)
| CVE | CVSS | Severity | Description |
| CVE-2026-76504 | 9.8 | Critical | Authentication bypass in Cisco Catalyst SD-WAN Manager allowing unauthenticated admin API access. |
| CVE-2026-20209 | — | High | Included in same advisory/disclosure; unauthorized file access vulnerability. |
| CVE-2026-20210 | — | High | File access / Information disclosure vulnerability. |
| CVE-2026-20224 | — | High | Additional vulnerability affecting SD-WAN Manager confidentiality and integrity. |
Note: Cisco initially categorized the three companion vulnerabilities as "High Severity" without publishing complete CVSS breakdown scores at the initial time of release.
