Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Updated Sep 30, 2026

Frequently Asked Questions About the Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)

Cisco disclosed the Authentication Bypass in Cisco Catalyst SD-WAN Manager, which lets an unauthenticated attacker gain admin-level access to the management API. This FAQ is updated as more details about the vulnerability and its fix emerge.

Status

CVE

CVE-2026-76504

CVSS

9.8 (v3.1)

Exploitation

In The Wild

CISA KEV

Listed

Vendor patch

Available

Questions

Updates

Key takeaways

What is CVE-2026-76504?

The Authentication Bypass in Cisco Catalyst SD-WAN Manager is a weakness in how the product handles session-based logins for its management API. Because the software mishandles a certain type of character encoding in web requests, an attacker can craft a request that slips past a rule meant to block outside access to one specific API endpoint. No account or password is needed.

A successful attack gives the attacker access to the Cisco Catalyst SD-WAN Manager API with the same privileges as the built-in admin account, which by default can perform any operation the system supports. That level of access could let an attacker view or change the configuration of every SD-WAN device the Manager controls.

CVEDescriptionCVSSExploited in the wild
CVE-2026-76504Authentication Bypass in Cisco Catalyst SD-WAN Manager9.8 Critical (CVSS 3.1)Yes

Is CVE-2026-76504 being exploited in the wild?

CVE-2026-76504 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on September 30, 2026.

How did CVE-2026-76504 come to light?

Cisco published its advisory for the Authentication Bypass in Cisco Catalyst SD-WAN Manager on September 30, 2026. Reporting on the advisory states that Cisco found the issue while its Technical Assistance Center was working through a customer support case – ultimately identifying exploitation in-the-wild.

How is watchTowr helping Cisco Catalyst SD-WAN Manager customers?

  • Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.

What is Cisco Catalyst SD-WAN Manager?

Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage, is centralized management software that lets network teams configure, monitor, and control an organization’s software-defined wide area network from a single dashboard, administering many connected devices.

Which Cisco Catalyst SD-WAN Manager versions are affected?

ProductAffected VersionsFixed Version
Cisco Catalyst SD-WAN Manager (releases earlier than 20.9)Earlier than 20.9Migrate to a fixed release
Cisco Catalyst SD-WAN Manager 20.920.920.9.10.1
Cisco Catalyst SD-WAN Manager 20.1220.1220.12.8.2
Cisco Catalyst SD-WAN Manager 20.1520.1520.15.6.1
Cisco Catalyst SD-WAN Manager 20.1820.1820.18.4.1
Cisco Catalyst SD-WAN Manager 26.126.126.1.2.1
Cisco Catalyst SD-WAN Manager 26.226.226.2.1
Cisco SD-WAN Cloud (Cisco Managed)Before 20.15.60520.15.605 (no customer action required)
  • Cisco states the vulnerability affects Cisco Catalyst SD-WAN Manager regardless of how the system is configured.
  • Systems with network ports reachable from the internet face the greatest risk, according to Cisco.
  • By default the admin account holds the netadmin role, which can perform any operation on the device.

Organizations should prioritize Cisco Catalyst SD-WAN Manager instances with management ports reachable from the internet, since Cisco says these face the greatest risk of compromise.

How do I fix CVE-2026-76504?

Cisco has released fixed software for every affected release train and recommends upgrading affected systems on an emergency basis. There is no workaround; until an upgrade is applied, Cisco advises blocking access from untrusted networks and placing the system behind a firewall that admits only known, trusted hosts.

  1. Preserve logs and run the admin-tech command on Cisco Catalyst SD-WAN Manager before making any changes.
  2. Review the service-proxy and vmanage-server log files for login requests from unknown or unauthorized IP addresses.
  3. Restrict network access to Cisco Catalyst SD-WAN Manager from the internet and allow only trusted, known hosts.
  4. Upgrade affected systems to the fixed release listed for their release train.
  5. Open a Cisco TAC case with the CVE number in the title if compromise is suspected.

How do I check Cisco Catalyst SD-WAN Manager for compromise?

Cisco’s advisory points to two log files on the Manager: the service proxy access log and the vmanage server log. Security teams should look for login requests tied to a specific authentication endpoint that come from unknown or unauthorized addresses, including requests made under reserved system account names. Cisco warns these entries can also appear during normal operation, so they must be compared against usual network activity before being treated as a sign of compromise.

What types of threat actors typically exploit this vulnerability?

Historically, APT groups and other attackers have exploited earlier Cisco Catalyst SD-WAN Manager vulnerabilities.

Have there been similar Cisco Catalyst SD-WAN Manager vulnerabilities before?

Yes. These earlier Cisco Catalyst SD-WAN Manager vulnerabilities were added to the CISA KEV catalog after exploitation in the wild:

CVEDescriptionAdded to KEV
CVE-2026-20262Cisco Catalyst SD-WAN Manager Directory or Path Traversal VulnerabilityJune 15, 2026
CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output VulnerabilityJune 9, 2026
CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityMay 14, 2026
CVE-2026-20122Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs VulnerabilityApril 20, 2026
CVE-2026-20133Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityApril 20, 2026
CVE-2026-20128Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format VulnerabilityApril 20, 2026
CVE-2026-20127Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass VulnerabilityFebruary 25, 2026
CVE-2018-0155Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service VulnerabilityMarch 3, 2022

If you are a watchTowr client

Rapid Reaction has identified and validated exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act. Contact your watchTowr team with any questions.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.