Attackers bypass authentication in Cisco’s SD-WAN manager console

CISA has ordered federal agencies to patch a critical Cisco SD-WAN Manager flaw that attackers are already exploiting.

CSBadmin
2 Min Read

Cisco’s central console for software-defined networks has a flaw that attackers are already exploiting, and the US government has now ordered federal agencies to patch it.

The vulnerability, tracked as CVE-2026-76504, carries a CVSS score of 9.8. It stems from improper handling of URI encoding in an HTTP request, letting an unauthenticated, remote attacker slip past an authentication rule and reach an API endpoint with the privileges of the admin user.

The Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog. Federal civilian agencies have until October 3, 2026, to apply fixes and run a compromise assessment.

Cisco learned its platform was under attack in September 2026, after a Technical Assistance Center support case pointed to real-world exploitation. The company has not said who is behind the activity or how many organizations were hit.

Every release from 26.2 back through 20.9 is affected, along with anything older than 20.9. Patches exist for versions 20.9 to 26.2; anyone on a build older than 20.9.10.1 has to migrate, because Cisco shipped no workaround.

Defenders can hunt through the serviceproxy-access.log and vmanage-server.log files for j_security_check requests from unknown addresses, and for accounts whose names start with viptela-reserved-. “Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited vulnerabilities list,” said Jake Knott of watchTowr, noting eight Cisco SD-WAN CVEs have landed there in 2026 alone.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.