Back to Blog
Vulnerabilities & Exploits

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

CISA has confirmed active exploitation of a critical authentication bypass in Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-76504. Federal agencies had until 3 October 2026 to remediate. Every other operator should treat the flaw as urgent too.

PyramidLedger Research3 min read
Share

Key Takeaways

  • CVE-2026-76504 is a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager, and CISA has added it to the Known Exploited Vulnerabilities (KEV) catalogue.
  • An unauthenticated remote attacker can send a crafted HTTP request to the API and gain access as the admin user.
  • Exploitation was discovered in September 2026, so hunt for compromise as well as patching.
  • The Federal Civilian Executive Branch deadline was 3 October 2026. Private-sector teams should use the same deadline as a benchmark.

What happened

CISA has added an authentication bypass in Cisco Catalyst SD-WAN Manager to its KEV catalogue, confirming that attackers are exploiting it in the wild. The flaw is tracked as CVE-2026-76504 and carries a CVSS score of 9.8. As reported by The Hacker News, the root cause is a hex-encoding weakness in how the product handles URIs.

An unauthenticated remote attacker can send a crafted HTTP request to the API of an affected system and gain access to the API as the admin user. Exploitation was discovered in September 2026. Federal Civilian Executive Branch agencies were given until 3 October 2026 to remediate.

Why it matters

SD-WAN Manager is a control plane. It holds the configuration and policy for the whole overlay network, so admin-level API access means an attacker can change how traffic flows across every site. It does not stop at one host. A bypass that needs no credentials and no user interaction, and that is reachable over HTTP, is about as bad as an edge-management flaw gets.

This is also not a one-off. Jake Knott of watchTowr noted that Cisco SD-WAN "feels like an ever-present staple" of the KEV list, with eight 2026 CVEs from the product line added this year alone. If you run this platform, assume that attackers are watching it and plan your patch process accordingly.

What defenders should do

  • Identify exposure. Inventory every SD-WAN Manager instance and check whether its management interface is reachable from the internet or from untrusted network segments.
  • Apply Cisco's fix. The source article does not list affected or fixed versions, so take them from Cisco's own advisory for CVE-2026-76504 rather than from third-party summaries.
  • Hunt for prior compromise. Patching does not remove an attacker who is already in. Review /var/log/nms/containers/service-proxy/serviceproxy-access.log for j_security_check requests from unknown IPs.
  • Check the application log too. Look in /var/log/nms/vmanage-server.log for j_security_check calls using usernames that start with viptela-reserved-.
  • Review the configuration. If you find suspicious access, audit changes to users, templates and policies, and rotate any credentials and keys the manager holds.

Treat the KEV deadline as a benchmark

The KEV deadline is binding only for US federal agencies. The catalogue is still a useful signal for everyone else, because it lists only vulnerabilities with confirmed exploitation. Many teams use it as a trigger for emergency patching, with the CISA date as the target. Given that exploitation began in September, any instance that was exposed before patching deserves an investigation, not just an upgrade.

Frequently asked questions

See the FAQ below for short answers on exposure, patching and detection.

Frequently Asked Questions

What is CVE-2026-76504?

It is a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager. A hex-encoding flaw in URI handling lets an unauthenticated remote attacker send a crafted HTTP request and gain admin access to the API. CISA has confirmed active exploitation.

How can I tell if my SD-WAN Manager was targeted?

Look for `j_security_check` entries from unknown IPs in the service-proxy access log. Also look for `j_security_check` calls with usernames beginning `viptela-reserved-` in the vmanage server log. Treat any hit as a possible compromise and start incident response.

Does the CISA deadline apply to my organisation?

Only federal civilian agencies are legally bound by KEV deadlines. For everyone else it is a sensible benchmark, because KEV entries are confirmed as exploited in the wild.

Sources

  1. 1CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV — The Hacker News
  2. 2Known Exploited Vulnerabilities Catalog — CISA
Share

Read next