Vulnerability
Published 2026-09-30
Verified 2026-10-01

Cisco Catalyst SD-WAN Manager CVE-2026-76504 (CVSS 9.8): unauth API→admin — exploited; CISA KEV added 1 Oct

Cisco PSIRT advisory cisco-sa-sdwan-webauth-xr8beuuU (first published 30 September 2026 13:00 GMT) covers CVE-2026-76504 (CVSS 3.1 9.8 Critical; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in Cisco Catalyst SD-WAN Manager API session-based authentication. Improper URI encoding lets an unauthenticated remote attacker bypass an authentication rule and access the API as the admin user (default netadmin). Affects Catalyst SD-WAN Manager regardless of configuration. Cisco PSIRT became aware of active exploitation in September 2026 (found via TAC case); no public victim count or actor named. Fixed trains: earlier than 20.9 → migrate; 20.9.10.1; 20.12.8.2; 20.15.6.1; 20.18.4.1; 26.1.2.1; 26.2.1. Cisco SD-WAN Cloud (Cisco Managed) already remediated in 20.15.605 (no customer action). No workaround; until patched restrict Manager from untrusted/internet networks and follow Catalyst SD-WAN Hardening Guide. Hunt j_security_check (incl. URI-encoded variants such as /%6a_security_check) in serviceproxy-access.log and vmanage-server.log, especially viptela-reserved- users. Distinct from older desk cisco-sd-wan-2026 (CVE-2026-20127/20128/20122 joint advisory) and May/June SD-WAN zero-days. Primary: Cisco; wire: The Hacker News / BleepingComputer 30 Sep. UPDATE 1 Oct 2026: CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog (The Hacker News 1 Oct), citing hex-encoding/URI handling that grants unauthenticated admin API access; federal due dates apply for FCEB. Wire: THN KEV item 1 Oct.

Product
Cisco Catalyst SD-WAN Manager (vManage)
Versions
Affected: Catalyst SD-WAN Manager all configurations on vulnerable release trains. Fixed: 20.9.10.1; 20.12.8.2; 20.15.6.1; 20.18.4.1; 26.1.2.1; 26.2.1; earlier than 20.9 migrate. Cloud (Cisco Managed) 20.15.605 already fixed.
CVSS
(CVSS 3.1 Critical)
Exploited in Australia?
unknown
Patch to
Upgrade Manager to first fixed release for your train (20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1); Cloud Managed customers need no action. Until patched: restrict internet exposure; hunt encoded j_security_check IoCs.

Primary: Cisco — Catalyst SD-WAN Manager API auth bypass (CVE-2026-76504, 30 Sep 2026) · Vendor: Cisco Security Advisory cisco-sa-sdwan-webauth-xr8beuuU · CVE: CVE-2026-76504, CVE-2026-20127 · The Hacker News — CISA adds Cisco SD-WAN Manager CVE-2026-76504 to KEV (1 Oct 2026)

vulnerabilities network cloud