Cybersecurity 3 min read

Cisco Found an Exploited SD-WAN Flaw While Handling a Customer's Support Case

CVE-2026-76504 lets an attacker with no password use Catalyst SD-WAN Manager's API as the administrator. It was exploited before the 30 September fix, and there is no workaround.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 1 Oct 2026, 7:09 AM (SGT)
Share:
Network cables plugged into the back of a router Network cables plugged into the back of a router Photo by moebiusdream on Pixabay
Advertisement

1 OCT 2026 — Cisco fixed a critical flaw in Catalyst SD-WAN Manager on 30 September, and by then attackers were already using it. The flaw lets someone with no password use the product's API as the administrator. Cisco found it while working on a customer's support case.

The US Cybersecurity and Infrastructure Security Agency added the flaw, CVE-2026-76504, to its list of exploited vulnerabilities the same day and gave federal agencies until 3 October to act.

What the flaw does

SD-WAN Manager, formerly vManage, is the central console organisations use to configure and control the routers in their software-defined wide-area networks. Whoever controls it can change how traffic moves between an organisation's offices and data centres.

Cisco's advisory says the product mishandles URL encoding in an HTTP request. A request that encodes one character of a particular path slips past an authentication rule and reaches the API "as the admin user". The flaw affects the product regardless of configuration, and there is no workaround.

9.8Severity score out of 10
30 SeptAdvisory and fixes published; CISA listing
3 OctDeadline for US federal agencies
No workaroundOnly upgrading fixes it; restricting access reduces exposure

Exploited before the fix

Cisco says its product security team became aware of active exploitation in September. The advisory says the flaw itself "was found during the resolution of a Cisco Technical Assistance Center (TAC) support case", meaning a customer's problem led Cisco to the bug rather than an outside researcher.

What to look for in the logs

The advisory includes example log entries customers can search for. They show login-path requests with one character encoded, made from unknown addresses and involving system service accounts whose names begin "viptela-reserved". The examples are dated 29 September. Cisco notes that some of the same indicators can appear in normal operation, so each network must check them against its usual behaviour.

Who needs to act

Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Versions older than 20.9 must move to a fixed release. Cisco's cloud-hosted SD-WAN service has already been patched, so it needs no action.

Advertisement

Until they can upgrade, on-premises customers should block the manager from the internet or allow only known, trusted addresses, Cisco says. Rapid7 advises patching outside normal cycles and auditing systems for signs of compromise, and notes that this is separate from two earlier SD-WAN authentication bypasses this year. CISA's entry also flags the flaw for forensic triage, asking agencies to look for intrusion as well as patch.

A console that keeps getting hit

This is not the first exploited SD-WAN flaw this year. In July we reported a zero-day that had been exploited for months before disclosure. Singapore's cyber agency had already warned about Cisco products more often in 2026 than in any full year before.

Management consoles are attractive because one compromise reaches everything they control. Cisco's own hardening advice points to the same practical rule: the SD-WAN manager should not be reachable from the open internet at all.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement