On September 30, Cisco issued a warning about a significant security vulnerability in its Catalyst SD-WAN Manager, a crucial tool for managing Cisco SD-WAN networks. The vulnerability, identified as CVE-2026-76504, is actively being exploited by attackers, according to Cisco’s advisory.
Details of the Exploitation
The vulnerability, which carries a CVSS score of 9.8, allows an attacker without credentials to exploit the Manager’s API as if they were an admin user. This is possible due to the mishandling of URI encoding in HTTP requests within the Manager’s API responsible for login sessions. Such an exploitation can bypass authentication measures meant to secure an API endpoint.
The flaw was discovered during a support case handled by Cisco’s Technical Assistance Center (TAC) in September 2026. Cisco’s Product Security Incident Response Team has acknowledged the active exploitation of this vulnerability. The advisory, however, does not provide specifics on the number of affected customers or the nature of the attacks.
Who Needs to Update
This critical flaw impacts the SD-WAN Manager across all configurations, with no other Cisco products currently affected. Cisco has released fixed versions for various release trains, with users advised to upgrade to these versions promptly. The new updates were not included in previous advisories from May and June, which addressed other vulnerabilities.
For those using on-premise Managers, Cisco recommends limiting access from unsecured networks until updates are applied. Managers exposed to the internet are at greater risk, and it’s advised that access be restricted to trusted hosts only. Cloud-hosted environments have mitigation measures in place, but Cisco encourages testing these in user-specific environments.
Identifying and Addressing Compromise
Cisco has provided guidance for detecting signs of compromise. Administrators should check specific log files for entries related to the j_security_check path, which may appear altered due to URI encoding. It’s crucial to compare these entries against normal operations to avoid false positives.
If compromise is suspected, Cisco advises opening a Severity 3 support case, ensuring to include CVE-2026-76504 in the title. The advisory does not specify if updating will remove an attacker who already has access, echoing sentiments from earlier advisories that emphasized collecting a detailed admin-tech file prior to any updates.
This vulnerability follows a series of exploited flaws within Cisco’s SD-WAN products, with the U.S. Cybersecurity and Infrastructure Security Agency noting eight such issues in 2026 alone. Organizations are urged to take immediate action to secure their systems against this significant threat.
