Vulnerabilities · 2h ago

Cisco SD-WAN Manager Auth Bypass Is Being Exploited

Cisco says attackers are already exploiting CVE-2026-76504 in Catalyst SD-WAN Manager, turning a critical authentication-bypass bug into an active risk for SD-WAN management planes. The issue affects multiple 20.x and 26.x release lines.

The flaw sits in how the product handles URI encoding: an encoded path can be treated as a different, unauthenticated route before the login check fully applies, letting a remote attacker reach admin APIs without credentials. Cisco points to anomalous `j_security_check` requests and `viptela-reserved-*` accounts as signs the bypass may have been used.

If Catalyst SD-WAN Manager fronts network control for your environment, this is exposure on the administrative layer itself, not just on one web endpoint. A patch closes the bug, but any already-abused admin access or configuration change would live beyond the fix until the logs and accounts are understood.

CVE-2026-76504

NVD KEV

CVSS 9.8 CRITICAL: a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…

Timeline

Sources

5 sources covering this story

Entities

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories