Cisco Catalyst SD-WAN Manager Zero-Day Actively Exploited for Admin Access
A critical zero-day vulnerability, **CVE-2026-76504**, in **Cisco Catalyst SD-WAN Manager** is being actively exploited, allowing unauthenticated remote attackers to gain administrative control. This flaw, with a CVSS score of 9.8, enables attackers to bypass authentication and execute privileged operations on affected devices. **Cisco** has released patches and urges immediate upgrades.
Attackers are currently exploiting a critical zero-day flaw in **Cisco Catalyst SD-WAN Manager**, the central system for managing **Cisco SD-WAN** networks. **Cisco** disclosed the vulnerability in an advisory on September 30, confirming active exploitation.
The flaw, identified as **CVE-2026-76504**, carries a severe CVSS score of 9.8 out of 10. It allows a remote attacker, without any prior authentication, to leverage the Manager's API as the admin user. The vulnerability resides in the API's login session handling mechanism.
### Technical Details of the Exploit
The **Cisco Catalyst SD-WAN Manager** mishandles URI encoding within HTTP requests. By crafting a specific request, an attacker can bypass an authentication rule designed to restrict access to a particular API endpoint. This means no credentials are required; only the ability to send the malicious request to the Manager's API is needed.
Systems directly exposed to the internet are particularly vulnerable. By default, the admin user holds the `netadmin` role, granting full operational control over the device.
**Cisco's Product Security Incident Response Team (PSIRT)** became aware of active exploitation in September 2026. The vulnerability was initially discovered during a support case handled by **Cisco's Technical Assistance Center (TAC)**. The advisory did not specify the number of affected customers, the start date of the attacks, the identity of the attackers, or the scope of their activities post-compromise.
### Immediate Action Required: Who Needs to Upgrade
The vulnerability impacts **SD-WAN Manager** irrespective of its configuration. **Cisco** has released fixed versions for various release trains. Customers using earlier versions (older than 20.9) must migrate to a fixed release.
| Release train | First fixed release |
| :----------------- | :------------------ |
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
It's crucial to note that **CVE-2026-76504** is distinct from previous **Cisco SD-WAN** vulnerabilities patched earlier this year, including **CVE-2026-20182** (May), **CVE-2026-20245**, and **CVE-2026-20262** (June). A Manager updated for those prior fixes still requires this new update.
**Cisco SD-WAN Cloud (Cisco Managed)** environments are already patched in release 20.15.605, requiring no action from those customers. For on-premise deployments, **Cisco** advises restricting access to the Manager from untrusted networks. If internet access is mandatory, it should be limited to known, trusted hosts, and control components should be protected by a firewall.
**Cisco Catalyst SD-WAN Cloud Hosted** environments already have these mitigations in place. **Cisco's** hardening guide emphasizes that administrative interfaces (e.g., ports 443, 22, 830) should never be directly exposed to the internet; HTTPS access to the Manager should only originate from a jump host or a dedicated management subnet.
### Detecting Signs of Compromise
**Cisco** has provided indicators of compromise (IoCs) focusing on `j_security_check`, the request path used by the Manager for session-based logins. Attackers may use URI encoding, such as `/%6a_security_check` (where `%6a` represents 'j').
Administrators should review the following log files for entries containing `j_security_check` from unknown or unauthorized IP addresses:
* `/var/log/nms/containers/service-proxy/serviceproxy-access.log`
* `/var/log/nms/vmanage-server.log` (specifically entries for users beginning with `viptela-reserved-`, which are reserved system service accounts)
Since any character in the request path can be encoded, and `j_security_check` entries can occur during normal operations, each match requires careful scrutiny to avoid false positives.
For assistance in determining compromise, customers can open a Severity 3 case with **Cisco TAC**, including "**CVE-2026-76504**" in the title. Before doing so, running `request admin-tech` on the Manager is recommended for log collection.
It's important to note that the advisory does not provide detection rules or confirm whether upgrading alone removes an existing attacker. Previous advisories for **Cisco SD-WAN** flaws indicated that updates alone would not resolve confirmed compromises, advising customers to collect `admin-tech` files before upgrading.
This vulnerability follows a series of **Cisco SD-WAN** flaws actively exploited this year. As of September 30, the **U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog** listed eight **Cisco SD-WAN** flaws added in 2026, underscoring the ongoing threat landscape for these critical network management systems.