Executive Summary

On September 30th, 2026, Cisco disclosed a critical vulnerability in Cisco Catalyst SD-WAN Manager and confirmed it has been exploited in the wild. Tracked as CVE-2026-76504, the flaw lets an unauthenticated, remote attacker bypass authentication on the Manager's API and gain access with the privileges of the admin user. The vulnerability affects SD-WAN Manager regardless of system configuration.

Catalyst SD-WAN Manager (formerly vManage) is the central management plane for Cisco SD-WAN deployments, controlling configuration and policy across the branch routers and edge devices in the fabric. This is the latest in a series of authentication flaws in Catalyst SD-WAN control components exploited during 2026, and Cisco has released fixed software for all supported release trains.

Cisco's Product Security Incident Response Team became aware of active exploitation in September 2026. Given the administrative control the SD-WAN Manager holds over enterprise networks and the repeated targeting of Cisco SD-WAN infrastructure this year, Beazley Security recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise.

Affected Systems or Products

The affected product is Cisco Catalyst SD-WAN Manager. The following table from the Cisco advisory details the specific versions.

Product

Affected Version

Fixed Version

20.9

< 20.9.10.1

20.9.10.1

20.12

< 20.12.8.2

20.12.8.2

20.15

< 20.15.6.1

20.15.6.1

20.18

< 20.18.4.1

20.18.4.1

26.1

< 26.1.2.1

26.1.2.1

26.2

< 26.2.1

26.2.1

Wording implies that fixes will not be released for versions earlier than 20.9, as the official recommendation from Cisco is to migrate to a fixed release.

Mitigations / Workarounds

Cisco has not recommended any workarounds outside of upgrading to a fixed release.

If on-premises deployments cannot be upgraded immediately, the following actions may help mitigate some risk:

  1. 1.

    Block access to the SD-WAN Manager from untrusted networks, including the internet.

  2. 2.

    Where internet access is required, restrict it to known, trusted hosts on only the ports and protocols the Cisco user guides require.

  3. 3.

    Place SD-WAN control components behind a firewall or other filtering device, and allow HTTPS management access only from a jump host or dedicated management subnet.

These actions may affect current network functionality, so clients should evaluate and test in their environments first. Upgrading to the fixed release Is still recommended even if these mitigations are in place.

Patches

Cisco SD-WAN Cloud (Cisco Managed) deployments have already been fixed by the vendor in release 20.15.605 and require no customer action, and Cisco Catalyst SD-WAN Cloud Hosted environments already have the network mitigation in place. Cisco has released fixed software for on-premises Managers, and additional information can be found in the official Cisco security advisory.

Indicators of Compromise

Cisco has confirmed active exploitation of this vulnerability in the wild but have not provided details on the threat actors or victimology. They did, however, provide details on some observed attack strings that can be used to threat-hunt against device logs.

Exploitation appears to specifically target the j_security_check API endpoint, and involves URI-encoded characters. Cisco's example demonstrates the string /%6a_security_check (where %6a is the letter "j"), but it should be noted an attacker can encode any single character in the request. Defenders should review the following logs for j_security_check requests from unknown or unauthorized IP addresses:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • /var/log/nms/vmanage-server.log

Cisco also offers assistance to organizations needing help determining whether their Manager device has been compromised. Such clients are directed to open a Severity 3 case with Cisco TAC, include CVE-2026-76504 in the title, and provide the admin-tech file for review.

Technical Details

In-depth technical details of the bug causing CVE-2026-76504 have not been published, but the indicators of compromise and description of the vulnerability hint at the root cause.

CVE-2026-76504 is described as an authentication bypass in the API session-based authentication management of SD-WAN Manager. API endpoints typically include code to ensure processing is only done for authenticated requests.

An attacker who encodes a single character in the request path apparently bypasses these checks, so it can be assumed that the filtering logic does not account for these characters. The result is API access as the admin user, without needing credentials.

Cisco found the flaw while resolving a Technical Assistance Center support case. No public proof-of-concept is known to be available at the time of writing.

How Beazley Security is responding

Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.