1 OCT 2026 — Cisco fixed a critical flaw in Catalyst SD-WAN Manager on 30 September, and by then attackers were already using it. The flaw lets someone with no password use the product's API as the administrator. Cisco found it while working on a customer's support case.
The US Cybersecurity and Infrastructure Security Agency added the flaw, CVE-2026-76504, to its list of exploited vulnerabilities the same day and gave federal agencies until 3 October to act.
What the flaw does
SD-WAN Manager, formerly vManage, is the central console organisations use to configure and control the routers in their software-defined wide-area networks. Whoever controls it can change how traffic moves between an organisation's offices and data centres.
Cisco's advisory says the product mishandles URL encoding in an HTTP request. A request that encodes one character of a particular path slips past an authentication rule and reaches the API "as the admin user". The flaw affects the product regardless of configuration, and there is no workaround.
Exploited before the fix
Cisco says its product security team became aware of active exploitation in September. The advisory says the flaw itself "was found during the resolution of a Cisco Technical Assistance Center (TAC) support case", meaning a customer's problem led Cisco to the bug rather than an outside researcher.
What to look for in the logs
The advisory includes example log entries customers can search for. They show login-path requests with one character encoded, made from unknown addresses and involving system service accounts whose names begin "viptela-reserved". The examples are dated 29 September. Cisco notes that some of the same indicators can appear in normal operation, so each network must check them against its usual behaviour.
Who needs to act
Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Versions older than 20.9 must move to a fixed release. Cisco's cloud-hosted SD-WAN service has already been patched, so it needs no action.
Until they can upgrade, on-premises customers should block the manager from the internet or allow only known, trusted addresses, Cisco says. Rapid7 advises patching outside normal cycles and auditing systems for signs of compromise, and notes that this is separate from two earlier SD-WAN authentication bypasses this year. CISA's entry also flags the flaw for forensic triage, asking agencies to look for intrusion as well as patch.
A console that keeps getting hit
This is not the first exploited SD-WAN flaw this year. In July we reported a zero-day that had been exploited for months before disclosure. Singapore's cyber agency had already warned about Cisco products more often in 2026 than in any full year before.
Management consoles are attractive because one compromise reaches everything they control. Cisco's own hardening advice points to the same practical rule: the SD-WAN manager should not be reachable from the open internet at all.