What is CVE-2026-76504?
The Authentication Bypass in Cisco Catalyst SD-WAN Manager is a weakness in how the product handles session-based logins for its management API. Because the software mishandles a certain type of character encoding in web requests, an attacker can craft a request that slips past a rule meant to block outside access to one specific API endpoint. No account or password is needed.
A successful attack gives the attacker access to the Cisco Catalyst SD-WAN Manager API with the same privileges as the built-in admin account, which by default can perform any operation the system supports. That level of access could let an attacker view or change the configuration of every SD-WAN device the Manager controls.
| CVE | Description | CVSS | Exploited in the wild |
|---|---|---|---|
| CVE-2026-76504 | Authentication Bypass in Cisco Catalyst SD-WAN Manager | 9.8 Critical (CVSS 3.1) | Yes |
Is CVE-2026-76504 being exploited in the wild?
CVE-2026-76504 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on September 30, 2026.
How did CVE-2026-76504 come to light?
Cisco published its advisory for the Authentication Bypass in Cisco Catalyst SD-WAN Manager on September 30, 2026. Reporting on the advisory states that Cisco found the issue while its Technical Assistance Center was working through a customer support case – ultimately identifying exploitation in-the-wild.
How is watchTowr helping Cisco Catalyst SD-WAN Manager customers?
- Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
What is Cisco Catalyst SD-WAN Manager?
Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage, is centralized management software that lets network teams configure, monitor, and control an organization’s software-defined wide area network from a single dashboard, administering many connected devices.
Which Cisco Catalyst SD-WAN Manager versions are affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Cisco Catalyst SD-WAN Manager (releases earlier than 20.9) | Earlier than 20.9 | Migrate to a fixed release |
| Cisco Catalyst SD-WAN Manager 20.9 | 20.9 | 20.9.10.1 |
| Cisco Catalyst SD-WAN Manager 20.12 | 20.12 | 20.12.8.2 |
| Cisco Catalyst SD-WAN Manager 20.15 | 20.15 | 20.15.6.1 |
| Cisco Catalyst SD-WAN Manager 20.18 | 20.18 | 20.18.4.1 |
| Cisco Catalyst SD-WAN Manager 26.1 | 26.1 | 26.1.2.1 |
| Cisco Catalyst SD-WAN Manager 26.2 | 26.2 | 26.2.1 |
| Cisco SD-WAN Cloud (Cisco Managed) | Before 20.15.605 | 20.15.605 (no customer action required) |
- Cisco states the vulnerability affects Cisco Catalyst SD-WAN Manager regardless of how the system is configured.
- Systems with network ports reachable from the internet face the greatest risk, according to Cisco.
- By default the admin account holds the netadmin role, which can perform any operation on the device.
Organizations should prioritize Cisco Catalyst SD-WAN Manager instances with management ports reachable from the internet, since Cisco says these face the greatest risk of compromise.
How do I fix CVE-2026-76504?
Cisco has released fixed software for every affected release train and recommends upgrading affected systems on an emergency basis. There is no workaround; until an upgrade is applied, Cisco advises blocking access from untrusted networks and placing the system behind a firewall that admits only known, trusted hosts.
- Preserve logs and run the admin-tech command on Cisco Catalyst SD-WAN Manager before making any changes.
- Review the service-proxy and vmanage-server log files for login requests from unknown or unauthorized IP addresses.
- Restrict network access to Cisco Catalyst SD-WAN Manager from the internet and allow only trusted, known hosts.
- Upgrade affected systems to the fixed release listed for their release train.
- Open a Cisco TAC case with the CVE number in the title if compromise is suspected.
How do I check Cisco Catalyst SD-WAN Manager for compromise?
Cisco’s advisory points to two log files on the Manager: the service proxy access log and the vmanage server log. Security teams should look for login requests tied to a specific authentication endpoint that come from unknown or unauthorized addresses, including requests made under reserved system account names. Cisco warns these entries can also appear during normal operation, so they must be compared against usual network activity before being treated as a sign of compromise.
What types of threat actors typically exploit this vulnerability?
Historically, APT groups and other attackers have exploited earlier Cisco Catalyst SD-WAN Manager vulnerabilities.
Have there been similar Cisco Catalyst SD-WAN Manager vulnerabilities before?
Yes. These earlier Cisco Catalyst SD-WAN Manager vulnerabilities were added to the CISA KEV catalog after exploitation in the wild:
| CVE | Description | Added to KEV |
|---|---|---|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | June 15, 2026 |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | June 9, 2026 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | May 14, 2026 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | April 20, 2026 |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | April 20, 2026 |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | April 20, 2026 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | February 25, 2026 |
| CVE-2018-0155 | Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability | March 3, 2022 |
