CVE-2026-76504 is an authentication bypass, rated 9.8 (critical), in Cisco Catalyst SD-WAN Manager (formerly vManage), the console that configures and controls an organization's SD-WAN routers across all of its sites. Cisco says an unauthenticated, remote attacker can send a crafted HTTP request to the API, slip past an authentication rule through improper handling of URI encoding, and gain access as the admin user. It affects SD-WAN Manager regardless of configuration, and Cisco says there are no workarounds.
Cisco's advisory, first published September 30, 2026, states that Cisco PSIRT became aware of active exploitation in September 2026. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 30, with a federal remediation deadline of October 3. Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; releases earlier than 20.9 must migrate to a fixed release. Cisco-managed cloud deployments were fixed by Cisco and need no customer action.
Recommended action:Find out this week whether your network uses Cisco Catalyst SD-WAN and whether its Manager runs on premises or in Cisco's managed cloud. Hospitals with clinics in several towns and municipalities linking offices often do, frequently through a carrier or managed service provider, so ask them directly. If it is on premises, upgrade to the fixed release for your train listed in Cisco's advisory. Until then, block access to the Manager from the internet and allow only known, trusted hosts, as Cisco recommends; Cisco's temporary Live Protect shield can add partial cover but does not replace the upgrade. Then check for intrusion: review /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for requests to an encoded j_security_check from unknown addresses, especially for users whose names begin with viptela-reserved-. If you find them, open a Cisco TAC case as Cisco describes, assume the attacker could have changed router configurations at every site, and handle it under your incident response plan.