Skip to main content

[SECURITY ALERT] Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504) — Actively Exploited

  • September 30, 2026
  • 0 comments
  • 13 views

CMF
Forum|alt.badge.img+8
  • Veeam Legend

A critical vulnerability (CVSS 9.8) has been identified in Cisco Catalyst SD-WAN Manager and is confirmed to be actively exploited in the wild. An unauthenticated remote attacker can gain administrative privileges and fully control the SD-WAN infrastructure via the management API. Given the central role of SD-WAN managers, this represents a severe risk to the entire WAN infrastructure.

  1. Affected Systems and Versions Affected Product: Cisco Catalyst SD-WAN Manager (formerly vManage)

The vulnerability stems from improper handling of the login endpoint (j_security_check), where specially crafted or encoded requests can bypass authentication.

Vulnerable Versions:

  • Prior to 20.9: All versions

  • 20.9.x: Versions prior to 20.9.10.1

  • 20.12.x: Versions prior to 20.12.8.2

  • 20.15.x: Versions prior to 20.15.6.1

  • 20.18.x: Versions prior to 20.18.4.1

  • 26.1.x: Versions prior to 26.1.2.1

  • 26.2.x: Versions prior to 26.2.1

  1. Action Items and Recommendations

Priority 1: Apply Security Updates Immediately Cisco strongly recommends upgrading immediately to the following safe releases:

  • Release Train 20.9 -> Fixed in 20.9.10.1

  • Release Train 20.12 -> Fixed in 20.12.8.2

  • Release Train 20.15 -> Fixed in 20.15.6.1

  • Release Train 20.18 -> Fixed in 20.18.4.1

  • Release Train 26.1 -> Fixed in 26.1.2.1

  • Release Train 26.2 -> Fixed in 26.2.1

  • Cisco SD-WAN Cloud -> 20.15.605

 

Priority 2: Check for Indicators of Compromise (IoC) Cisco suggests inspecting the following log files for signs of exploitation:

  • /var/log/nms/serviceproxy-access.log

  • /var/log/nms/vmanage-server.log

Search for: /%6a_security_check

The presence of this string alone does not confirm a successful breach, but it indicates potential attack attempts and should be thoroughly investigated.

Priority 3: Restrict Management Access Until patches can be applied:

  • Block all public internet access to the SD-WAN Manager.

  • Restrict access strictly to trusted administrative networks or VPNs.

  • Enforce management port restrictions via firewalls.

  • Minimize external exposure.

These steps follow standard Cisco and incident response best practices for actively exploited management plane vulnerabilities.

Official Cisco References

3. Related CVEs (Sorted by Severity)

CVE CVSS Severity Description
CVE-2026-76504 9.8 Critical Authentication bypass in Cisco Catalyst SD-WAN Manager allowing unauthenticated admin API access.
CVE-2026-20209 — High Included in same advisory/disclosure; unauthorized file access vulnerability.
CVE-2026-20210 — High File access / Information disclosure vulnerability.
CVE-2026-20224 — High Additional vulnerability affecting SD-WAN Manager confidentiality and integrity.

Note: Cisco initially categorized the three companion vulnerabilities as "High Severity" without publishing complete CVSS breakdown scores at the initial time of release.