Attackers Are Logging In as Admin on Cisco SD-WAN Manager Without a Password

A crafted request bypasses login on Cisco Catalyst SD-WAN Manager and grants admin API access. Cisco confirms exploitation; fixed releases are out.

Get Advisory Support
Critical CVE-2026-76504

CVE-2026-76504 is an authentication bypass, rated 9.8 (critical), in Cisco Catalyst SD-WAN Manager (formerly vManage), the console that configures and controls an organization's SD-WAN routers across all of its sites. Cisco says an unauthenticated, remote attacker can send a crafted HTTP request to the API, slip past an authentication rule through improper handling of URI encoding, and gain access as the admin user. It affects SD-WAN Manager regardless of configuration, and Cisco says there are no workarounds.

Cisco's advisory, first published September 30, 2026, states that Cisco PSIRT became aware of active exploitation in September 2026. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 30, with a federal remediation deadline of October 3. Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; releases earlier than 20.9 must migrate to a fixed release. Cisco-managed cloud deployments were fixed by Cisco and need no customer action.

Recommended action: Find out this week whether your network uses Cisco Catalyst SD-WAN and whether its Manager runs on premises or in Cisco's managed cloud. Hospitals with clinics in several towns and municipalities linking offices often do, frequently through a carrier or managed service provider, so ask them directly. If it is on premises, upgrade to the fixed release for your train listed in Cisco's advisory. Until then, block access to the Manager from the internet and allow only known, trusted hosts, as Cisco recommends; Cisco's temporary Live Protect shield can add partial cover but does not replace the upgrade. Then check for intrusion: review /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for requests to an encoded j_security_check from unknown addresses, especially for users whose names begin with viptela-reserved-. If you find them, open a Cisco TAC case as Cisco describes, assume the attacker could have changed router configurations at every site, and handle it under your incident response plan.

← All security bulletins

Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.

Worried about a bulletin above?

We can assess your exposure to the threats above and other active campaigns, and help you remediate quickly.

Request an Exposure Check